We personalize our customers' journeys with our energy and engineering solutions; We produce efficient, safe and sustainable projects.

Follow Us
Follow Us

Privacy Policy

PRIVACY POLICY GMR Engineering & Energy

Effective Date: November 13, 2025
Last Update: November 13, 2025

As GMR Energy Engineering, we attach great importance to the privacy and security of your personal data. This Privacy Policy explains how personal data collected through our Company's corporate website is processed in compliance with all relevant data protection legislation, especially the European Union General Data Protection Regulation (GDPR), the Republic of Turkey Personal Data Protection Law (KVKK), the United States California Consumer Privacy Act (CCPA/CPRA), the Brazilian General Data Protection Law (LGPD). Within the scope of the policy:

  • What personal data we collect,
  • By what methods and on what legal basis we collect this data,
  • For what purposes we use your data,
  • Use of cookies and similar technologies,
  • With whom personal data may be shared (including third parties and international transfers),
  • How long we keep data and our security measures,
  • Rights of data owners and additional regional rights (for Türkiye, EU/EEA, California, Brazil),

We aim to inform you on topics such as. This Privacy Policy also serves as a clarification text prepared in accordance with article 10 of KVKK.

Identity and Contact Information of the Data Controller
In accordance with KVKK and other data protection laws, the "data controller" is the organization that determines the purposes and means of processing the collected personal data and is GMR Engineering & Energy.

Title: GMR Engineering & Energy
Address: Kızılırmak Mah. Dumlupınar Blv. Next Level No: 3A/10, Çankaya, Ankara, Türkiye
Phone: +90 (312) 911 50 86
Email: info@gmrmuhendislik.com

For any questions, requests or feedback, you can contact us via the contact information above.

1. Personal Data Collected

We may collect different categories of personal data when you use our website or contact us:

  • Identity and Contact Information: Data such as name, surname, e-mail address, telephone number (if requested in the form), company or institution information where you work. This information is generally data provided directly by you through the contact and application forms on our website.
  • Message and Content Information: The content of the messages, requests or feedback you send to us through contact forms or application forms. The information you provide to us in this section may include other personal data relevant to your request (for example, data from your CV if it is a job application).
  • Usage Data: There is some information that is collected automatically when you visit our website. This includes log records and analytical data such as your IP address, browser type, device type, operating system, which pages you visited on our site and the date and time of visit. This data may be obtained through cookies and similar tracking technologies.
  • Preference Information: Data to customize your user experience, such as your preferred language selection or other preferences on our website (which may be retained through cookies).
  • Marketing Contact Data: If you have registered to receive e-bulletin subscription or campaign notifications, your name, surname, e-mail and related preferences collected in this context. It is collected if you give marketing consent.
  • Technical Data: Technical data such as device identifiers and system error records collected for security and system health purposes. For example, if we use firewall services to ensure site security, IP and device information may be collected for suspicious activity.

While some of the specified data (such as contact form data) is provided directly by you, some of it (such as usage data received through cookies) is collected by automatic methods. We strive to collect only necessary and relevant data whenever possible. We do not knowingly collect sensitive personal data (race, ethnicity, political opinion, religion, health information, biometric data, etc.) through our website. We recommend that you do not share such sensitive information in your messages.

2. Personal Data Collection Methods and Legal Basis

Collection Methods: Your personal data is obtained mainly in the following ways:

  • Forms: When you fill out the contact or application forms on our website, the information you provide (identity, contact and message contents) is transmitted to our system.
  • Automated Technologies: Your usage data is collected automatically through cookies and similar technologies placed on your browser during your visit to our site. Server logs and security tools may also automatically collect data about your visit.
  • Direct Contact: If you send us an e-mail or contact us by phone, the personal data you share through these channels may be collected.
  • Third Party Sources: Generally, we do not collect personal data from other sources through our website. However, if you contact us, for example, through a social media account, that platform may transmit some information to us (such as your username). In this case, data is received according to the privacy settings of the platform in question.

Legal Basis: We process your personal data in accordance with relevant laws, based on the following legal reasons:

  • Explicit Consent: In some cases, you must give prior consent before we can process your data. In particular, we request your explicit consent to send marketing emails (e-newsletter subscription) or run analytical/preference-based cookies. You have the right to withdraw your explicit consent at any time.
  • Establishment or Performance of the Contract: The requests you submit through the forms on our site, such as receiving a product/service offer or job application, may be requests that may turn into a contract in the future. In such cases, your personal data is processed if it is directly related to the establishment or execution of the contract upon your request.
  • Legitimate Interest: We may process your data within the scope of our legitimate interests, such as ensuring the security of our website, preventing fraud and abuse attempts, and answering the questions you send us. For example, if you fill out the contact form, it is in our legitimate interest to use your contact information to respond to your request. While relying on our legitimate interests, we consider the possible impact on your fundamental rights and freedoms and maintain balance.
  • Legal Liability: In some cases, we may have to process your data in order to fulfill our legal obligations. For example, it is a legal obligation to take necessary actions to respond to legal requests of competent authorities or to fulfill our obligation of transparency to you in accordance with KVKK/GDPR.
  • Prescribed by Law & Other Reasons: We may process personal data within the framework of other legal bases specified in regulations such as KVKK art.5 and GDPR art.6, in cases clearly stipulated by law, in life-threatening situations, when it is necessary for the establishment, exercise or protection of a right, or when the data is made public. For example, within the scope of the exceptions provided for in KVKK, we may process data to the extent permitted by law without obtaining your separate consent.

Information: Whenever we request your personal information, we try to explain to you why we request this information and on what legal basis we rely. Your provision of data is completely voluntary; However, if we do not fill in the required fields, we may not be able to provide the service you request or get back to you.

3. Purposes of Use of Personal Data

We use the personal data we collect for the following purposes:

  • Contact and Feedback: We use the information you share with us through the contact or application form to meet your requests, answer your questions and communicate with you. For example, if you submit a quote request through our website, we will use your contact information to get back to you.
  • Providing Services and Information: We may process your data for purposes such as informing you about the information, documents or services you request, sending documents or setting appointments. For example, to inform you about the evaluation process if you have applied for a project.
  • Marketing Communications: Provided that you have your explicit consent, we can send company news, e-bulletins, information about our new services or campaigns to your e-mail address. If you do not wish to receive such marketing communications, you can unsubscribe at any time.
  • Improving Website Experience: We use usage data obtained through cookies and analytics tools to analyze how you use our website. These analyzes aim to increase site performance, improve our content and improve user experience. For example, we can improve navigation by identifying the most frequently visited pages or content.
  • Personalization: We may use your data to give you a more personalized experience by remembering your settings, such as your preferred language. For example, presenting content according to your preferences when you revisit the site.
  • Security and Fraud Prevention: We process your data to ensure the security of our systems and to detect and prevent fraudulent or malicious activities. IP addresses and logs can be used to track potential threats. In this way, we take the necessary measures to protect both your and our data.
  • Compliance with Legal Obligations: We may use your data to comply with legal requirements such as accounting, tax, government reporting or sharing of personal data as a result of a court order or administrative request. In addition, data may be processed for purposes such as keeping records and reporting to competent authorities, in line with our disclosure obligation and data security obligations under KVKK and GDPR.
  • Internal Reporting and Administrative Purposes: We may also use data for internal purposes such as evaluating our service quality, analyzing our business processes, and preparing statistical reports. In such transactions, if possible, attempts are made to anonymise the data or to remove your personal identification information.
  • Exercise of Legal Rights: In case of a possible legal dispute, we may use the relevant records and information if necessary to establish, exercise or defend our legal rights. For example, log records of our past communications may be used as evidence in the event of a dispute.

If we need to process your personal data for a purpose other than the stated purposes, we will only do so if legally permitted and, if necessary, we will obtain your prior consent. Your personal data will never be used for purposes other than those specified in this policy.

4. Marketing Communications and Explicit Consent

Marketing Approval: Our use of the contact information you provide through our website (especially e-mail) to send you electronic messages for marketing purposes is legally subject to your express consent. For example, we can send you newsletter, announcement or campaign information via e-mail if you consent by subscribing to a newsletter or by selecting an option such as "I would like to receive information" in the contact form. Otherwise, you will not receive promotional or marketing e-mails without your consent.

How We Communicate: Our marketing communications will generally take the form of email newsletters. Methods such as SMS or phone call may also be used from time to time; However, such methods are also carried out in accordance with the relevant legal legislation (e.g. Law No. 6563 on the Regulation of Electronic Commerce in Turkey) and with your approval when necessary.

Unsubscribe: Even if you have once consented to receive marketing communications, you reserve the right to change your mind. There is an unsubscribe link at the bottom of the e-mails sent by us. You can stop receiving marketing emails at any time by clicking on this link or by contacting us directly (for example, by emailing “I do not want to receive any more”). When we receive your request, we will remove you from our list within the legal period (for example, within 3 business days at the latest in Turkey). Withdrawing your consent does not affect the legality of the transactions up to that point.

Targeted Ads: We do not currently display targeted advertising on our website through third-party ad networks. Therefore, personalized ad serving via marketing cookies or similar tracking tools is not possible. If we implement such a practice in the future, we will obtain your prior consent and give you the opportunity to control "advertising cookies".

Sharing with Friends: Our website may contain buttons for you to share our content on social media. If you indirectly direct visitors to us by sharing content, this may be considered a marketing activity; But even in this case, your personal data will not be subjected to additional processing by us. Your information is used only within the framework of the social media platform's own privacy settings.

In summary, we do not send you any advertisements, promotions or mass e-mails unless you give permission. You can update your marketing preferences at any time or cancel them completely.

5. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to improve user experience, analyze site traffic and provide certain functions. This section explains our use of cookies and your choices.

What is a Cookie? A cookie is a small text file placed on your device through your browser when you visit a website. This file contains some information about the site and allows your device to be recognized on subsequent visits. Thanks to cookies, it is possible, for example, to remember your previous preferences or keep you logged in when you enter the site again.

Types of Cookies We Use:

  • Mandatory Cookies: These are cookies that are absolutely necessary for the website to function. The site cannot function properly without these cookies, so they are not subject to user consent. For example, session cookies, security cookies or cookies that remember you when filling out a form are in this group.
  • Analytical Cookies: It collects anonymous data about how our visitors use the site. It is used to obtain statistics such as which pages receive the most attention and the time spent on the site. This information helps us improve the performance and content of our site. For example, third-party analytics tools such as Google Analytics may be used. The use of analytical cookies is subject to user consent in most countries, so you will be asked to consent to analytical cookies when you first access our site.
  • Optional (Functional) Cookies: These are cookies that customize your site experience by remembering your preferences. It allows us to remember your language option, page layout preferences or other customizations you have made on the site. These cookies enhance functionality but are not essential; may therefore be subject to your approval.
  • Targeting Cookies: These are cookies that can be used for advertising and marketing purposes (although not currently implemented). They can be used to show content and advertisements that are similar to your interests or to present our advertisements on different platforms after your site visit. If we use such cookies in the future, we will seek your express consent.
  • Third Party Cookies: Cookies from third-party providers may also operate on our website. For example, if you watch a video hosted on YouTube on our site, YouTube may place its own cookies on your device. Likewise, “Share” buttons or social media plugins may also set cookies of the relevant platforms. The use of third-party cookies is subject to the respective parties' own privacy policies.

Cookie Preferences: When you first come to our website, you may be shown a notice informing you about our use of cookies (cookie alert). You can accept analytics and preference-based cookies by consenting to this notice. If you don't want it, you will have the option to reject it or customize it. You can also block cookies completely or delete previously placed cookies through your browser settings. However, we would like to remind you that in this case, some functions of our site may not work properly. Rejecting cookies other than essential cookies will not prevent you from using the site in general; However, you may need to re-adjust settings, such as your language preference, each time you visit.

Storage Periods of Cookies: Some cookies remain active throughout your browser session (until you close the site), while others may remain on your device for longer. You can view site-based cookies and learn their lifetime through your browser settings. You can also clear your browser history and cookies at any time.

Cookie Policy: For more detailed information on the use of cookies, you can view our Cookie Policy (if available). Our use of cookies is presented transparently in an integrated structure with this Privacy Policy.

6. Sharing of Personal Data and Transfer to Third Parties

We undertake to keep your personal data confidential within ourselves and not to share it unnecessarily with third parties. In no case do we sell, rent or generate revenue from your data to third parties. However, in some cases, we may need to share your data with third-party service providers or business partners in order to continue our activities and serve you. In this section, we explain the parties with whom data may be shared and the reasons:

  • Hosting and IT Services: The company that provides the server infrastructure on which our website is hosted (hosting service) and other IT companies from which we receive technical services such as maintenance and backup may technically access your data. For example, if the server on which our website is located is in a data center at home or abroad, the operator of this data center may see your IP address or form messages in the server logs. Confidentiality and data protection obligations are defined in the contracts made with these service providers.
  • Email and Communication Services: Your messages sent via contact forms or e-mail pass through the servers of our e-mail service provider. For example, if we use a service such as Microsoft Office 365 or Google Workspace for our company e-mail service, message contents may be processed on the servers of these services. Similarly, if a third-party email delivery service (Mailchimp, Sendinblue, etc.) is used for e-newsletter submissions, your name and email information may be uploaded to this platform.
  • Customer Relationship Management (CRM) and Databases: If we use a CRM software or cloud-based service to keep our customer and contact information organized, the data you share with us may be saved in these systems. Providers of such systems (such as Salesforce, HubSpot) may have technical access to your information in their capacity as data processors, but may not use it except under our instructions.
  • Analytical and Monitoring Tools: Analytics tools, such as the previously mentioned Google Analytics, collect and report visitor data. In this context, companies such as Google transmit your usage data (IP address, visit duration, page interactions, etc.) to their servers and report it through cookies placed on your browser. However, these data are generally anonymous statistics that do not directly identify you, such as name and e-mail. However, since data such as IP address may be involved, such sharing can also be considered as data transfer. Agreements with these providers ensure that the data is used only on our behalf and for the purposes we have described.
  • Payment and Billing Systems: Online payment infrastructure providers (iyzico, PayPal, Stripe, etc.) or billing integrations may process personal data (even though online orders or payments are not taken directly through our site, in case of a future service sale). In such cases, sensitive data such as payment information is generally received directly by the relevant payment institution and our Company does not provide full access to this data.
  • Legal, Finance and Consulting Services: We can work with attorneys, auditors or consultants as needed. For example, in a legal dispute, we may need to provide your relevant communication records to our lawyer, or certain records may be examined by auditors during an audit. In these cases too, these professionals are under a duty of confidentiality and may only use your information for the relevant purpose.
  • Group Companies: (If GMR Engineering & Energy is part of a group company) data may be shared with other companies within the group for certain administrative procedures or joint services. If such sharing is currently the case, the relevant companies are under data protection obligations at least as much as we are.
  • Pursuant to Legal Obligations, Buyers: We may share your personal data with these recipients upon request by legally authorized public institutions and organizations (such as courts, prosecutors' offices, police units, Personal Data Protection Authority) or when a legal obligation arises. This sharing will be limited only to the extent requested and within the scope of the relevant legal obligation (for example, the provision of certain records pursuant to a court order).
  • Processing and Business Transfers: If our company undergoes a corporate transaction such as a merger, acquisition, restructuring or asset sale, your personal data may be among the transferred assets. In such a case, the receiving party will be obliged to continue processing your data in accordance with this policy.

Relations with Data Processors: Many of the third parties with whom we share your personal data are data processors; That is, they process your data only on our behalf and in accordance with our instructions. The contracts we make with these parties (e.g. confidentiality agreements, data processing annexes) contain provisions necessary to protect your data. In particular, obligations such as not using the data for purposes other than its intended purpose, taking adequate security measures and deleting the data at the end of the contract are defined.

Third Party Sites: We may provide links to other sites (sites of our business partners, social media platforms, etc.) from our website. These sites have their own privacy policies and we are not responsible for the content or practices of these sites. When you go to a third-party site, we encourage you to review your own privacy preferences and terms of that site.

We Do Not Sell Data: We would especially like to emphasize that under no circumstances do we sell, license or share your user data with third parties for commercial gain. Sharing is done only within the framework of the legitimate purposes stated above and to the extent necessary. For example, data may be shared with a company that provides technical infrastructure to provide a service, but your data will not be given to another company for marketing purposes without your consent. We do not engage in any transactions that would be considered a “sale” under the laws of the State of California (CCPA/CPRA), nor do we “share” your personal information with third parties for cross-context targeted advertising.

7. International Data Transfers

As GMR Engineering & Energy, due to the nature of our activities and the technological infrastructures we use, there may be situations where we may transfer your personal data abroad. We work with servers, cloud services or business partners in different countries. For this reason, there may be scenarios such as processing data collected in Turkey on a server abroad or processing a request from the European Union in Turkey.

Transfers Outside Türkiye (KVKK): In accordance with Article 9 of KVKK, the transfer of personal data abroad is subject to certain conditions. As a company, when transferring your data to a country outside Türkiye:

  • Countries Where Adequate Protection Decision Has Been Given by the Board: We may transfer to countries declared to have adequate protection by the Personal Data Protection Authority (KVKK Board). (Note: The KVKK Board has not yet declared such a “safe country” list, so this route does not actually exist.)
  • If There Is Not Adequate Protection: If there is not sufficient protection in the country to which we will transfer the data, we, as data controllers in Turkey and the relevant foreign country, undertake the necessary protection in writing and obtain the permission of the Board or request your explicit consent for the relevant data transfer. In practice, we usually obtain your express consent for the international services we use (for example, by accepting analytical cookies you also consent to data going abroad).
  • If there are other exceptions stipulated by KVKK (conditions in Articles 5(2) or 6(3) of the Law, even if there is no explicit consent), international transfer may also be possible in this case. For example, if it is mandatory for the performance of a contract or if there is a legal claim.

European Economic Area (EEA) / Non-UK Transfers (GDPR): In accordance with the European Union General Data Protection Regulation (GDPR), we take similar precautions when transferring personal data across EU/EEA borders. If we send your data to a country outside Europe (e.g. the USA):

  • Adequacy Decision: No additional permission is required for transfers to countries determined by the European Commission to have an adequate level of protection. (For example, the United Kingdom has been deemed sufficient by the EU; some countries such as Switzerland etc. are also included in the list.)
  • Appropriate Assurances (Standard Contractual Clauses etc.): If the country is not sufficient, we will implement appropriate safeguards set out in Clause 46 GDPR, such as Standard Contractual Clauses with the receiving party. These agreements stipulate that data receives EU-level protection even in the country from which it is received. If necessary, additional technical/organizational measures are taken (for example, transferring data by encrypting it).
  • Exceptional Situations: GDPR Data transfer abroad can also be made within the framework of the exceptions in Article 49 (explicit consent, performance of a contract, legal request, etc.). In particular, transfer outside the EU may be carried out if there is your explicit consent.
  • In any case, we take all necessary precautions to protect your privacy in international data transfers. For example, if we have a service provider in the USA and we have signed SCC (Standard Contractual Clauses) with that provider, this means that there are binding contractual guarantees for the protection of your data.

Transfers Outside Brazil (LGPD): Brazil's LGPD law similarly regulates the transfer of personal data abroad. If data obtained from Brazil is to be transferred to another country, there must be adequate protection in the relevant country or security safeguards approved by the Brazilian Data Protection Authority (ANPD) must be implemented (e.g. standard contracts or company binding rules). Our company transfers data from Brazil outside the country only under the conditions permitted by LGPD.

In Which Situations Does Transfer Occur?: In practice, the most common examples of international transfers are:

  • The server on which our website and email service is hosted is located in a country outside Europe (e.g. the USA or another region).
  • If the servers of the third party services we use (Google, Microsoft, Mailchimp, etc.) are abroad.
  • If you are visiting the site from outside Türkiye, your data will naturally be transmitted to Turkey and other locations.
  • If we need to transmit your data to our business partners abroad within the framework of a request (e.g. sharing your contact information with a company we cooperate with for an international project).

Transparency: If you have questions about which countries your personal data can be transferred to, you can contact us and request details. For example, “Is my analytics data going to the US?” You may ask; We will also inform you in which country the tool we use processes data.

Situations Requiring Explicit Consent: In some cases, it may be safest for us to obtain your explicit consent to data transfer in order to comply with both KVKK and GDPR.

For example, If data transfer is required to a country with which EU legislation is not fully compliant, we may request confirmation of this at the beginning of the site. If you choose not to give this consent, we will try to keep your data within Türkiye/EU as much as possible or restrict the relevant services for you (for example, we will not perform analytics).

Example: Let's say our website's hosting service is received from a US-based company. In this case, when you enter our website, your IP address and browsing data will be transmitted to servers in the USA. For GDPR, this is considered a data transfer. We ensure that your data remains safe by signing SCC with this company and taking technical security measures (encryption, etc.). At the same time, we may have obtained your explicit consent with a warning in the cookie notification such as "By using this site, you also agree to the transfer of your data to the USA."

In summary, we protect your personal data regardless of the country. We comply with all applicable legal regulations in international data transfers and implement contractual, technical and administrative measures to ensure the security of your data.

8. Storage Period of Personal Data

We retain the personal data we collect for the period required for the relevant purposes and in accordance with applicable legislation. When determining retention periods, we take into account the nature of the data, the purpose of processing and the legal obligations to which it is subject. Our general retention policy is as follows:

Contact Data: The messages and contact information you send through contact forms are stored for the time required to respond to your request and carry out the necessary follow-up. For example, after we receive a response from you, we may keep our correspondence for a reasonable period of time for quality control or to use as evidence in future disputes. This period is typically set at no more than 2 years, but if an ongoing business relationship has arisen (for example, you have become our customer) your data may be retained for longer as part of your customer file.

  • Contact Data: The messages and contact information you send through contact forms are stored for the time required to respond to your request and carry out the necessary follow-up. For example, after we receive a response from you, we may keep our correspondence for a reasonable period of time for quality control or to use as evidence in future disputes. This period is typically set at no more than 2 years, but if an ongoing business relationship has arisen (for example, you have become our customer) your data may be retained for longer as part of your customer file.
  • Marketing Data: We store the data we process for marketing communications, such as your email address, until you unsubscribe or the relevant marketing activity ends. When you unsubscribe, we may need to keep your address on a “blocked” list so that we no longer send you emails (to avoid accidentally adding it again). However, it is not actively used for marketing. The maximum periods stipulated by law are also taken into account in this regard.
  • Cookie Data: Cookies are set to remain in your browser for certain periods of time. For example, session cookies are deleted when you close the browser, while some preference cookies may remain on your device for several months or years. The lifetime information of the cookies used on our site can be seen in the cookie policy or in your browser settings. We may store analytical data, usually in anonymized form, for long-term trend analysis; However, this data does not identify you on an individual basis.
  • Job Applications: If you apply for a job via our website (sending an application form or CV by email), we will retain your application documents throughout the recruitment process and for a reasonable period thereafter. If your application is rejected, we may wish to retain your CV for future opportunities, but we usually require explicit consent to do so. If you do not give your consent, we will delete your CV within 2 years at the latest in accordance with the legislation.
  • Legal Periods: Some data must be stored for the periods stipulated by the relevant legal regulations. For example, accounting records (which may contain personal data, such as invoice information) are kept for 10 years in accordance with the Turkish Commercial Code and Tax Procedure Law. Similarly, destruction policy records, explicit consent records, etc. that must be kept in accordance with KVKK. certain periods of time are reserved.
  • Claims Status: In case a legal dispute arises between you and us, we may retain any data that may be necessary during the statute of limitations. For example, an application you make pursuant to KVKK and the response letters we provide will not be deleted until these processes are completed, as they will be required for proof if the KVKK Authority conducts an investigation in the future.
  • Anonymization: When we no longer need the data and we are not legally obliged to keep it, we will completely delete, destroy or anonymize this data.

Data whose retention period has expired, periodic destruction It is securely deleted, destroyed or anonymized within the scope of our processes. In accordance with KVKK and relevant regulations, our periodic destruction processes are carried out at least twice a year. For more detailed information, in-house Our Data Storage and Destruction Policy you can request (if we have a relevant policy).

9. Security of Personal Data

The security of your personal data is an indispensable priority for us. For this purpose, we implement a series of technical and administrative security measures. Some of the measures we take to ensure that your data is protected against risks of unauthorized access, disclosure, alteration or destruction include:

  • Encryption: Sensitive data transmitted through our website is encrypted using secure communication protocols (SSL/TLS). The lock symbol you see in your browser's address bar indicates that the traffic between you and the site is encrypted. Additionally, critical information in our databases is protected by cryptographic methods whenever possible.
  • Access Controls:Internally, we limit access to personal data to only authorized employees who have a business need for this data. Role-based access control is also applied for these employees, so not everyone can access all data. For example, only the customer relations department can access customer contact information, while only the IT department can access server logs.
  • Physical Security:The servers where our data is kept are hosted in secure data centers. These data centers are protected against physical risks such as fire and earthquake and have 24/7 security, camera monitoring and access control systems. Any physical documents or local servers in our company office are protected by measures such as locked cabinets and alarm systems.
  • Anti-virus and Security Software:Our systems are protected against malware with up-to-date anti-virus programs. Additionally, additional technical measures such as firewalls, intrusion detection and prevention systems (IDS/IPS) and DDoS protection are implemented for our web application.
  • Update and Maintenance:The software and server systems we use are updated regularly. Patches released against security vulnerabilities are applied as soon as possible. We take care not to use old and unsupported systems. Our website is developed in accordance with secure coding principles and is periodically scanned for vulnerabilities.
  • Recording and Monitoring:We log authorized access and important transactions in our systems. In this way, we can investigate and trace any possible unauthorized access or data leakage attempt. Access logs are stored for a certain period of time and used only for security purposes.
  • Employee Training and Policies:We regularly provide data privacy and information security training to our employees. There is an Information Security Policy implemented within the company, and the rules that all our personnel are expected to comply with are defined. For example, we have procedures regarding external memory use, password policies, screen privacy, etc.
  • Data Breach Response Plan: Although we strive to provide the highest level of protection, we are prepared for the possibility of a security breach. In the event of a possible data breach, our Data Breach Response Plan is activated. Within the framework of this plan, steps to notify relevant users and authorities (for example, KVKK or the relevant supervisory authorities in the EU), reduce damage and prevent recurrence are defined.
  • Third Party Security:We ensure that third parties from whom we receive services comply with data security through contracts. For example, we ensure that our cloud service providers have international security certifications (such as ISO 27001). We may also, from time to time, request reports on security checks from these providers.

We would like to point out that despite all these measures, there is no such concept as "100% security" on the internet and digital systems. Although we provide the highest level of protection we can, the risk of breach due to emerging attack methods or unforeseen vulnerabilities is never zero. However, as users, you can also contribute to your security:

  • Even if you do not create an account on our website, please ensure the security of the devices you use to communicate with us (such as up-to-date anti-virus software, strong passwords, being cautious on public Wi-Fi).
  • If you notice anything suspicious (for example, an unexpected e-mail from us on your behalf), we kindly ask you to contact us immediately and report it.

In summary:We apply both technical security measures in accordance with international standards and internal policies to protect your personal data. We are constantly vigilant to prevent unauthorized access or misuse. In case of any security breach, we will notify you, our users, and authorized institutions by following the relevant legal procedures.

10. Data Owner Rights

The law gives you various rights to have control over your personal data. As GMR Engineering & Energy, we respect all data owner requests and fulfill the necessary procedures within legal periods. You have the following rights regarding your personal data processed by us:

  • Right to Information and Access: Learning whether we process personal data about you; If it is being processed, you have the right to request information regarding this. In other words, we can inform you which data we hold, for what purposes we use this data and with whom we share this data. For example, “what is my e-mail address and form messages registered in the system?” you may ask.
  • Right to Correction: You have the right to request correction of your personal data that you think has been processed incompletely or incorrectly. For example, if there is a typo in your name or your contact information has changed, you can request an update.
  • Right to Deletion (Forgotten): Under certain conditions, you can request the deletion or destruction of your personal data. For example, you can request the deletion of your data if the purpose for which it was processed is no longer valid or if it is no longer legally required to be stored. KVKK m. This right has been granted to you within the scope of Article 7 and GDPR article 17. We will evaluate your request in accordance with the legislation and take the necessary action. (Note: In some cases, for example if we are legally obliged to retain certain data, we may not be able to delete it immediately, but we will inform you in this case as well.)
  • Right to Restrict Processing: Although you have a right under GDPR, it is not directly regulated in KVKK; However, you can still request a temporary suspension of the processing of your data in certain cases. For example, if you have disputed the accuracy of your data, you can request that the data only be stored and not processed for any other purpose until your request is resolved.
  • Right to Data Portability:Within the scope of GDPR and partly LGPD, you can request that the personal data you have provided to us be transmitted to you or another service provider of your choosing in a structured, commonly used format. For example, if there is certain profile data you hold with us (such as an e-newsletter subscription), you can provide it to you in CSV/Excel format or, if technically possible, request that we transfer it directly to another platform.
  • Right of Objection:You have the right to object to certain circumstances in which your personal data is processed. In particular, you can object at any time to the processing of your data for direct marketing purposes (e.g. sending e-mail advertisements on your behalf); In this case, processing for marketing purposes is stopped immediately. Apart from this, you also reserve the right to object to transactions based on legal grounds of legitimate interest for reasons specific to your situation. In addition, you may object to a result against you arising from the analysis of your data processed exclusively through automatic systems in accordance with article 11 of KVKK.
  • Right to Withdraw Consent: If you have previously given consent to the processing of your personal data (e.g. marketing consent or cookie consent), you have the right to withdraw your consent at any time. From the moment you withdraw your consent, the relevant processing activity will be stopped and, if possible, your data will be deleted or anonymised. Withdrawing your consent does not affect the legality of transactions that took place before the withdrawal.
  • Right to Make a Complaint: If you believe that there has been any violation of the protection of your personal data, you can lodge a complaint with the relevant supervisory authorities. You can apply to the Personal Data Protection Authority (KVKK Board) in Turkey; If you are in a European Union country, you can file a complaint with your own country's data protection authority. In Brazil, you have the right to apply to the ANPD (National Data Protection Authority), and in California, you have the right to apply to the California Privacy Protection Agency or the State Department of Justice. We prefer to run our internal resolution mechanisms to assist you before you have any complaints, so we would be pleased if you contact us first.
  • Claiming Compensation:In accordance with Article 11 of KVKK, if you suffer any damage due to the unlawful processing of your personal data, you have the right to request compensation for this damage. Similarly, within the scope of GDPR, persons who have suffered damage as a result of the violation reserve the right to claim compensation. We hope such a situation never happens; However, if it does happen, we would like to remind you that you can exercise your rights in legal processes.

How can you exercise your rights?

You can contact us at any time to exercise your above rights or make any requests regarding your personal data. In accordance with KVKK article 13 and relevant legislation, you can submit your applications to us in writing or by other methods determined by the KVKK Board. For your convenience, you may prefer to contact us via email. To submit your requests, you can send an e-mail to info@gmrmuhendislik.com with the words "KVKK Application" or "Data Request" in the subject line. If possible, please provide your name and surname and details of the relevant request so that we can verify your identity. (For example, if you are writing from a different e-mail address, include your e-mail address registered in our system so that we can find you.)

We finalize the requests we receive within 30 days at the latest (as per KVKK). For requests within the scope of GDPR, this period is generally 1 month and can be extended to 2 months if necessary; However, in case of extension, we will inform you. As a rule, requests are processed free of charge. However, KVKK and GDPR reserve the right to charge a reasonable fee if your request is excessive and unnecessary duplication or if you request additional copies. So far, we have not requested such a fee from any user; Our aim is to always help you free of charge and quickly.

We may request additional information regarding your application to verify your identity. For example, in an e-mail application, sending a verification code to your phone number in our records or requesting a copy of your official ID. This is a precaution we take to protect your data; Because we do not want anyone else to make an unfair demand on your behalf.

When responding to your requests, we will notify you in writing that we have carried out the transaction or why we have not been able to complete it, along with the reasons, depending on the nature of the request. For example, you will receive a response such as “your personal data has been deleted from our system” or “we have to keep this data for such and such a period of time due to such and such legal obligation”.

As a result: We respect your rights over your personal data and care about transparency. We are ready to help you with any questions and requests. If you would like to get more detailed information about your rights, you can take a look at the relevant legal texts (KVKK art.11, GDPR art.15-22, CCPA Sec.1798.100 et seq. etc.) or ask us directly. Remember, data is your data; We are just custodians.

Additional Information Specific to Turkey (KVKK)

For our users residing in the Republic of Turkey and the relevant persons whose data are processed in Turkey, some additional information is provided below, in accordance with the Personal Data Protection Law No. 6698 (KVKK) and the relevant secondary legislation:

  • Data Controller: KVKK In accordance with Article 10, we have disclosed our identity as the data controller above under the heading "Identity of the Data Controller". GMR Engineering & Energy is a company based in Ankara and our contact information is exactly as stated there. If you wish, you can send your written requests to our company address by registered mail or send them through a notary. (For detailed information on application procedures, you can refer to the "Communiqué on Application Procedures and Principles to the Data Controller.")
  • Lighting Obligation: With this policy text, we inform you in accordance with Article 10 of KVKK. The personal data we collect/provide; Necessary information has been provided regarding the processing purposes, transfer parties, legal reasons and your rights. If there is any other information you request in accordance with KVKK that is not included in this text, we are ready to provide it to you.
  • Rights under KVKK: Article 11 KVKK grants certain rights to data owners (we have mentioned them in general terms in the “Data Owner Rights” section above). In particular, to remind you again, in accordance with Article 11 of KVKK, everyone can contact the data controller and; They have the right to learn whether their personal data has been processed, to request information if they have been processed, to learn their purpose, to know the third parties to whom they have been transferred domestically/abroad, to request correction if they have been processed incompletely/incorrectly, to request their deletion or destruction if the reasons for processing have disappeared, to request that the transactions performed be notified to third parties, to object if an adverse situation occurs as a result of analysis through automatic systems, and to claim compensation if they suffer damage due to unlawful processing. We have stated above the ways you can exercise these rights; We will finalize your requests within 30 days at the latest in accordance with KVKK.
  • Transfer of Data Abroad: We are subject to articles 8 and 9 of KVKK regarding the transfer of your personal data outside Türkiye. As we stated in the “International Data Transfers” section above, we apply for the assurances required by KVKK when data is transferred abroad. Since there is no safe country list announced by the Board yet, in practice we require your explicit consent for most international transfers. For example, if you consent by selecting the "I accept transfer abroad" option in the cookie pop-up on our website. If you do not give consent, we will try to process your data within the borders of Türkiye as much as possible.
  • Application and Complaint Mechanisms: To exercise your rights within the scope of KVKK, you must first contact us as the data controller. If you are not satisfied after receiving a response to your application or do not receive a response within 30 days, you can file a complaint with the KVKK Authority. The Institution's address and application procedures are available on the official website of KVKK. We wish to resolve disputes amicably; Therefore, you can send any questions or complaints to us first.
  • Data Security Violations: If there is a security breach regarding your data while you are in Turkey (for example, data leak), we will notify you and the Board as soon as possible in accordance with Article 12 KVKK. We are doing our best to prevent such a situation from ever happening, but we wanted to emphasize our obligation to inform in theory.
  • Other Relevant Legislation: There are also regulations applied in Turkey regarding the protection of personal data other than KVKK. For example, Law No. 6563 and Message Management System (IYS) rules apply to electronic marketing messages. We take care to act in compliance with all such legislation. We do not send you commercial electronic messages without your explicit consent. We respect your right to refuse via IYS.
  • Children: There is no specific age limit for processing children's personal data in Turkey. However, if we need to process data of users under 18 years of age, we will obtain parental/guardian consent if possible. Anyway, our website is generally aimed at adults; We do not knowingly request data from individuals under the age of 16. If a parent becomes aware that their child has provided us with data, please contact us and we will take action (deletion, etc.).

Additional Information for EU/EEA and UK (GDPR)

For our users residing in member states of the European Union or regions within the European Economic Area (EEA) (as well as those residing in the United Kingdom), we would like to highlight some additional points within the framework of compliance with the General Data Protection Regulation (GDPR) and the UK GDPR:

  • Representative of the Data Controller: If our company does not have a legal entity or representative within the EU, we may be required to appoint an EU representative according to Article 27 GDPR. As of now, we do not have a representative in the EU because our main target audience is in Turkey and we do not have a systematic activity in the EU. However, if our activities towards the EU market increase in the future, we will appoint a representative and include this information in our privacy policy.
  • Legal Basis: Within the scope of GDPR, we rely on a specific legal basis for each data processing activity (GDPR art. 6). In the "Legal Basis" section above, we explained in general terms which basis we use in which cases. In summary: we rely on appropriate articles such as contract (Art.6/1-b), legitimate interest (Art.6/1-f), legal obligation (Art.6/1-c), consent (Art.6/1-a) and, where necessary, vital interests (Art.6/1-d) or legally authorized public interest situations (Art.6/1-e). We would like to emphasize in particular that for users in the EU, we obtain consent for marketing emails and cookies; We do not engage in unauthorized marketing claiming legitimate interest.
  • Your rights: GDPR grants data subjects comprehensive rights (access, rectification, deletion, restriction, portability, objection, removal of the effect of automated decisions). We respect all of these rights. When an individual legally resident in the EU makes a request to us, we follow the procedures required by GDPR. For example, we will typically respond to your access request free of charge within 30 days. Although it is parallel to the procedures in Turkey, we note the points where GDPR differs. For example, data portability is not available on KVKK but is available on GDPR; If such a request comes from the EU, we will fulfill it.
  • Right to Complaint (DPA): Within the EU, if you are dissatisfied with the processing of your personal data, you can lodge a complaint with the data protection authority of your country of residence. For example, there are institutions such as FDPIC in Germany, CNIL in France, and Autoriteit Persoonsgegevens in the Netherlands. For the United Kingdom, the Information Commissioner's Office (ICO) is the competent authority. Although we think that our website does not directly market goods/services to EU citizens (evaluation within the scope of article 3 of GDPR), we would like to point out that if our users visit our site from the EU, they have this right.
  • International Transfers: 44-49 of GDPR regarding data transfer outside the EU/EEA (e.g. to Turkey or the USA). We are subject to the articles. We also apply the measures (Standard Contractual Clauses, etc.) that we have mentioned above under the heading "International Data Transfers" for EU data. For example, if the data of a user in the EU comes to our servers in Turkey, this is technically considered a third country transfer, although not as much as transferring it to the USA. In this case, we know that Turkey is not yet recognized as a "sufficient country" by the EU; that's why we resort to SCCs or exceptions. However, since our relationship with you is mostly on a one-time communication basis, we consider these transfers to be minimal and low risk.
  • Cookies (ePrivacy): In the EU, cookies and similar technologies are regulated by the ePrivacy Directive (2002/58/EC) and relevant country legislation. In this context, we offer our EU visitors the option to reject cookies and we use analytical/preference cookies only if they give their consent. If we have a cookie management tool (e.g. banner with “approve” and “reject” options), we pre-block all cookies customized for the EU. We also try to respect Do Not Track signals on a browser-by-browser basis (where possible).
  • Profiling and Automated Decisions: We do not track users through our website for profiling purposes or make automated decisions about them. Within the scope of GDPR Art.22, if there are automatic decision mechanisms that significantly affect your users, you must inform them. There is no such situation in our service; We do not use any resulting algorithms such as credit scores or automatic rejection/acceptance. If such an application occurs in the future (say, an automatic CV screening system, etc.), we will also specify its details and your right to object.
  • Data Protection Officer (DPO): According to art.37 GDPR, we may need to appoint a Data Protection Officer (DPO) if the scale of our activities requires it. Currently, we are not obliged to appoint a DPO since our data processing operations within the scope of our core activities do not involve large-scale sensitive data or we are not a public authority. However, we have designated an internal responsible person (who we can call the compliance officer KVKK) and this person coordinates data protection issues. If our business expands in the EU, we will consider appointing a DPO.
  • Compliance with Obligations: There are many compliance obligations imposed by GDPR (keeping data inventory, performing DPIA, breach notifications, contracts, etc.). We comply with these obligations in line with our company scale. In particular, we are aware that in the event of a data breach we must notify the relevant DPA within 72 hours and we have the necessary preparations. Nevertheless, we are working with all our strength to prevent such a violation from occurring.
  • UK Specific: The UK GDPR is substantially the same as the EU GDPR. The requirement to register with the ICO could come into play if we were doing a certain business there. We do not currently offer an active service to the UK market, but our website is of course accessible from the UK. We also apply the same EU standards of protection for users from the UK. We also take steps in accordance with ICO guidance.
  • Principle of Non-Possession: In accordance with EU principles (data minimization, purpose limitation, etc.), we only keep necessary data for the required period of time. We have already adopted these principles with KVKK; The same applies to the EU audience.
  • Language and Understandability: We prepared this policy in Turkish because our main audience reads Turkish; However, we do not want to disrespect anyone in the EU who does not speak Turkish. We can provide an English summary or full translation of the policy if necessary. If our company activities expand in the EU, it will be natural for us to make our privacy policy multilingual.

In summary, we take all necessary steps to meet GDPR's high standards. Our users in Europe benefit from the same rights and protections as users in Turkey, even with the additional advantages provided by GDPR. If you have any questions or would like to consult on a specific issue related to EU legislation, you can contact us without hesitation.

Additional Information for California, USA (CCPA/CPRA)

If you are a California resident, you have certain additional rights and protections regarding your personal data under California consumer privacy laws (California Consumer Privacy Act - CCPA, as updated, California Privacy Rights Act - CPRA). California law broadly defines the term “California resident” as a natural person who resides or is temporarily absent from California.

Although it is a matter of technical evaluation whether our company falls within the scope of CCPA/CPRA (according to criteria such as annual income, data processing volume), we also grant these rights to our users who are residents of California, as a matter of transparency and respect for user rights. Here are some highlights specific to California:

Categories of Personal Information We Collected in the Last 12 Months: As required by the CCPA, we are expected to disclose the categories and sources of personal information we have collected from consumers in the past 12 months. We have actually explained these in detail in the relevant sections of this Privacy Policy, but to summarize:

  • Identifiers: Information that identifies you, such as name, surname, e-mail address, telephone number (collected directly from you through contact forms, etc.).
  • Internet or Other Electronic Network Activity Information: Your browsing history, IP address, pages you clicked on the site, etc. collected through cookies and similar tools. usage data (collected by automated means).
  • Commercial Information: Our website is not an e-commerce site, so we do not collect commercial data such as purchase history or credit card information. However, if you have submitted a request, records related to that request (e.g. your request for quotation) may be included in this scope.
  • Professional or Educational Information: If you have applied for a job on our site, we may have processed the education and work experience information in your resume.
  • Geolocation Data: We do not collect your exact geographic location (such as GPS coordinate). An approximate location (by city) can be inferred from your IP address, but we do not obtain precise location data.
  • Audio/Visual Information: Our website does not request records such as photographs, videos, or audio from you, so we do not process data in this category.
  • Biometric Information: It doesn't add up.
  • Inferences: We do not engage in profiling that will reveal specific preferences or characteristics about you. For example, we do not derive an interest profile from your browsing history (although Google Analytics provides general interest reports, these are at an aggregate level, not an individual level).

Personal Information Sources: The above data has come directly from you, from automated systems through the use of the site, and if it is a job application, it has probably come directly from you. We do not collect data from a third data broker or public source.

Sharing for Business Purposes: We shared the personal information we collected with our service providers for “business purposes.” As we explained above in the "Data Sharing" section, your data may have been transferred to service providers such as hosting, e-mail and analytics. These service providers are considered "service providers" within the scope of the CCPA, and the contracts we make with them stipulate that they process your information only on our behalf and for the purposes we describe, as required by the CCPA. We have not sold or “shared” any of your personal information to a third party for targeted advertising purposes in the last 12 months. For this reason, there is no "Do Not Sell or Share My Personal Information" link on our website. Because we do not have any activities that legally require this. Note: While the term “sales” is broadly defined in the CCPA, there is no precedent for this in our business; We do not provide user data in exchange for money or any other benefit.

Your California Consumer Rights:

  • Right to Know: You have the right to learn from us what personal information we have collected about you in the last 12 months, its categories, sources, purposes of use and with whom it was shared. Upon request, we may also provide you with a copy of specific data we hold about you.
  • Right to Delete: Subject to certain exceptions, you may request that we delete the personal information we have collected. Yasal zorunluluk yoksa sileriz.
  • Right to Correction: Thanks to this right added by the CPRA, you can request that inaccurate information about you be corrected.
  • Right to Opt-Out from Selling/Sharing: You can request that your personal information not be sold to third parties or shared for targeted advertising purposes. We don't do anything like this anyway. If it happens in the future, we will add a “Do Not Sell or Share” link.
  • The Right to Restrict the Use of Sensitive Information: Under the CPRA, if we process sensitive data you can limit its use. Şu anda hassas veri işlemiyoruz.
  • Right to Non-Discrimination: We do not discriminate against you for exercising your rights.

Exercising Your Rights (California): You can exercise your rights by contacting us via e-mail. Claims must be verified; We may request additional information for identity verification. Per the CCPA, we will respond within 45 days (we may extend an additional 45 days if necessary).

Authorized Representative: You can exercise your rights through an agent in California. We may request documentation to verify the agent's authority.

Shine the Light Law: We declare that we do not share your personal data with third parties for their direct marketing purposes. However, we can provide information once a year if you request.

In summary, we uphold and respect California consumer rights. Even if our activities are not fully targeted by these laws, we adopt these principles due to our user-friendly approach. Users in California may request from us the rights introduced by CCPA/CPRA in addition to all general rights set forth in this policy. In the event of a dispute, we will comply with the guidance of the California State Attorney General or the California Privacy Protection Agency.

Additional Information for Brazil (LGPD)

For our users in Brazil, we share some additional information within the scope of Lei Geral de Protecao de Dados (LGPD). LGPD requires the processing of personal data for transparent, limited and legitimate purposes. As GMR Engineering & Energy, we aim to act in accordance with these basic principles for visitors from Brazil.

Processing Purposes and Legal Basis: Your personal data; We may process it in order to respond to communication requests, manage offer and application processes, ensure website security, improve our services and fulfill our legal obligations. These transactions within the scope of LGPD; Consent may be based on appropriate legal grounds such as conclusion or performance of a contract, fulfillment of legal obligation and legitimate interest.

Your Rights Under the LGPD: Data subjects in Brazil have the right to learn whether their personal data is being processed, to access their data, to request the correction of incomplete or inaccurate data, to request the deletion of unnecessary or excessive data, to request anonymization or portability of data, and to withdraw consent in certain cases. You can also request information about whether your data is shared with public or private organizations.

International Data Transfers: In data transfers outside Brazil, we observe the security and legality requirements stipulated by LGPD. Data is only transferred in cases where appropriate technical and administrative measures exist, within the framework of contractual guarantees or other necessary legal mechanisms.

Application and Complaint: You may submit your requests under the LGPD by emailing info@gmrmuhendislik.com. When reviewing your request, we may ask for additional information to verify your identity. You also have the right to lodge a complaint with Brazil's data protection authority, the ANPD (Autoridade Nacional de Protecao de Dados).

In summary, we are committed to transparent, secure and measured processing of personal data for our users in Brazil. If you want to exercise your rights under LGPD, you can contact us.

Children's Privacy

Our website and services are generally aimed at adults and businesses. We do not knowingly collect or request personal data from children under 16 years of age. If we know that you are under 16 years of age, we take care not to keep your data on our systems. Similarly, minors under the age of 18 are advised to use our website under the supervision of their parents or guardians.

Parental Approval: If there is a situation where a child under the age of 16 (for example, a child whose parent is you) needs to communicate with us, please make this communication instead of him/her or make sure that you provide your explicit consent. To protect children's privacy, if we become aware that a child has provided us with personal information, we will take steps to delete or anonymise that information from our records.

COPPA (Children's Online Privacy Protection Act): In the US, collection of data from children under 13 is subject to COPPA. We do not conduct an activity that falls within the scope of COPPA, as we do not offer any online services to those under the age of 13. If we unknowingly receive data from under 13s, we will immediately seek parental consent or remove the data from our systems in accordance with COPPA requirements.

Data Deletion Requests (Children): If you, as a parent or guardian, have concerns about data that you believe your child (under the age of 16) has shared with us, you can request deletion of that data by contacting us. When we receive such a request, we first confirm whether the data in question is actually linked to the child and then take the necessary action.

Rights of Minors: Users who are under 18 years of age and reside in California have the right to request the removal of content they post on our platform (California Business & Professions Code § 22581). However, our site is not a platform that allows users to publish content; Therefore, this law has no practical application.

In summary, we show all the sensitivity necessary to protect children's privacy. Our Services are not directed to children and we do not knowingly retain child data. If a contrary situation arises, please inform us so that we can take appropriate action.

Policy Updates

This Privacy Policy is a living document that may be updated from time to time. We may need to make changes to the content as technology, our services or legal requirements change.

Change Status: For example, if we start using a new third-party service, begin collecting additional categories of data, or make changes to our data sharing practices, we will update this policy. Again, we may need to revise the policy text to comply with changes in applicable law.

Notice: If we make significant changes, we will provide prominent notice on our website (e.g. in the form of a banner, pop-up or announcement on the home page). We may also send you update information via e-mail if we have your contact information and you have given your consent. For example, we may send a message to subscribers to our email newsletter saying “We have updated our Privacy Policy, please review it.”

Effective Date: The “Last Updated” date is stated at the top of the page. We update this date whenever a new version is released. The updated policy is deemed to come into force as soon as it is published on our website. Therefore, we recommend that you review this policy periodically. Although we will notify you of any significant changes, it's a good idea to check in yourself every once in a while.

Old Records: In case of significant policy changes, we may maintain an archive of previous versions. We will provide you with a review of previous versions upon request. However, generally, after the policy changes, the new policy applies prospectively and does not affect past transactions (unless legally required).

Continued Use: Your continued use of our website following the publication of the updated Privacy Policy will mean that you accept the changes. If you are not happy with any changes, please let us know or close your account/delete your data if necessary. However, most changes to our policy are generally positive or transparency-enhancing.

Contact and Application

You can contact us at any time with any questions, concerns or requests regarding our Privacy Policy or the processing of your personal data in general. Our contact information for data protection matters:

We would like to remind you again that we will finalize your applications within 30 days at the latest after receiving them. Depending on the nature of your application, we may request additional information from you or contact you to understand your request in more detail.

You can also contact us for general questions other than requests within the scope of exercising your rights. For example, if there is a part of this policy that you do not understand, you can ask for clarification. Or if you are curious about more details about the measures we take to protect your personal data, we may reasonably share it with you.

Finally, thank you for reading our privacy policy. We appreciate the trust you place in us regarding the security and privacy of your personal data. In order to maintain this trust, we will comply with all our legal obligations and adhere to our principle of transparency.

Engineering Tomorrow's Energy Today.

GMR Solar - Image of sustainable energy investment with solar panels