In accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Turkish Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu, “KVKK”), Stratejik İşler (“We”, “Data Controller”) — operator of the Hi Networking project (“Hi Networking”, “Platform”) — wishes to inform you, visitors and members of our website at hinetworking.com (“Website”), about our identity, the purposes of processing your personal data, to whom and for what purpose it is transferred, our legal bases, processing methods, and your rights.
1. Data Controller
Stratejik İşler
Abide-i Hürriyet Cd. No: 211/64, Şişli, İstanbul, Türkiye
Data protection contact: Stratejik İşler Data Protection Office — KVKK İrtibat Kişisi / Data Protection Contact
E-mail (data protection): privacy@hinetworking.com
E-mail (general): info@hinetworking.com
Web: hinetworking.com
Stratejik İşler acts as the “data controller” (veri sorumlusu) under the KVKK and as the “controller” under the GDPR for the processing described in this notice.
VERBİS (data controllers’ registry) status: Stratejik İşler is currently exempt from the obligation to register with the Data Controllers’ Registry Information System (VERBİS). The exemption relied upon is: Personal Data Protection Board Decision No. 2018/32 — data controllers with fewer than 50 annual employees and an annual balance sheet below the published threshold, whose principal activity is not the processing of special-category data. We monitor the thresholds and will register and publish the registration number here within the period granted by the Personal Data Protection Board if the exemption ceases to apply. Our personal data processing inventory is maintained regardless of the registration obligation.
2. Data Processing Principles
Your personal data processed during your use of the Platform is:
- Processed lawfully, fairly and in a transparent manner (Article 5(1)(a) GDPR)
- Collected for specified, explicit and legitimate purposes (Article 5(1)(b) GDPR)
- Adequate, relevant and limited to what is necessary (Article 5(1)(c) GDPR)
- Kept accurate and up-to-date where necessary (Article 5(1)(d) GDPR)
- Retained only for as long as necessary (Article 5(1)(e) GDPR)
- Processed with appropriate security measures (Article 5(1)(f) GDPR)
3. Personal Data Collected
- Identity Information: First name, last name
- Contact Information: Email address, phone number (optional)
- Professional Information: Role, company, industry, interests, expertise areas
- Account & Profile: Profile photo, biography, digital card data, social links
- Networking Data: Contacts, relationship notes, timeline events, voice notes and transcripts, follow-up reminders, opportunities
- Platform Usage Data: Event participation, messages, AI coach interactions
- Technical Data: IP address, browser information, cookie data, device type
4. Legal Bases for Processing
- Contract performance (Art. 6(1)(b)): Providing platform services and managing your membership
- Legitimate interest (Art. 6(1)(f)): Improving platform experience, analytics, and security
- Consent (Art. 6(1)(a)): Marketing communications, push notifications, optional AI features, and processing of voice recordings
- Legal obligation (Art. 6(1)(c)): Compliance with Turkish and EU legal requirements
Under the KVKK the corresponding conditions in Article 5(2) apply — processing necessary for the establishment or performance of a contract, compliance with a legal obligation, or our legitimate interests where your fundamental rights are not harmed — and your explicit consent under Article 5(1) is obtained for marketing communications, optional AI features and voice recordings. Special-category data (KVKK Art. 6) is processed only with explicit consent and only where you choose to provide it.
5. Purposes of Data Processing
- Creating and managing your membership account
- Providing platform features (smart profile, digital card, relationship memory, events, AI coach)
- Generating AI-powered summaries, conversation starters, transcripts and translations from data you submit
- Sending notification, reminder and communication emails
- Statistical analysis and reporting (in aggregated form)
- Fulfilling legal obligations under Turkish and EU law
- Ensuring platform security and preventing abuse
6. Data Transfers
Your personal data may be transferred to servers and service providers located in Türkiye, within the European Economic Area (EEA) and, where necessary, to other countries (including AI model providers) for the purpose of providing the Platform’s technical infrastructure services. Cross-border transfers are made on one of the bases permitted by Article 9 of the KVKK — your explicit consent, an adequacy decision of the Personal Data Protection Board, or a standard contract / binding company rules notified to the Board — and, where the GDPR applies, with the safeguards required by Chapter V of the GDPR (Standard Contractual Clauses or an adequacy decision). The vendors involved are listed on our Subprocessors page. Apart from this, your personal data is not shared with third parties except as required by legal obligations.
7. Data Retention Period
Your personal data is retained for the period required by the processing purpose and within the limitation periods prescribed by Turkish law (generally up to 10 years for contractual claims under the Turkish Code of Obligations No. 6098, and the retention periods required by the Turkish Tax Procedure Law and Law No. 6563). Upon termination of your membership, your data outside of legal retention periods will be deleted, destroyed, or anonymised within 30 days in line with our personal data retention and destruction policy under the KVKK, which sets out the retention period for each data category and our six-monthly periodic destruction cycle. Voice recordings stored in the Platform may be deleted by you at any time from your contact timeline.
8. Your Rights Under the KVKK & GDPR
As a data subject you have the rights listed in Article 11 of the KVKK and, where the GDPR applies to your data, the equivalent rights in Chapter III of the GDPR:
- Right of access (KVKK Art. 11(a)–(b), GDPR Art. 15)
- Right to rectification (KVKK Art. 11(d), GDPR Art. 16)
- Right to erasure (KVKK Art. 11(e), GDPR Art. 17) — “right to be forgotten”
- Right to restriction (GDPR Art. 18)
- Right to data portability (GDPR Art. 20)
- Right to object (KVKK Art. 11(g), GDPR Art. 21)
- Right regarding automated decisions (KVKK Art. 11(f), GDPR Art. 22)
- Right to compensation for unlawful processing (KVKK Art. 11(g))
- Right to lodge a complaint: You may submit a request through our KVKK application form or at privacy@hinetworking.com — we respond within 30 days under the KVKK (and within one month under the GDPR) — and you may then lodge a complaint with the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) at kvkk.gov.tr. If you are located in the EEA, you may also complain to your local supervisory authority.
9. Cookies
Our Website uses cookies and similar technologies. Essential cookies are necessary for the functioning of the Website and do not require consent. Non-essential cookies (analytics, preferences, marketing) are only placed with your explicit consent in accordance with the EU ePrivacy Directive (2002/58/EC) and Turkish Electronic Communications Law No. 5809. You can review categories, lifetimes and manage your choices at any time in our Cookie Policy or through your browser settings.
10. Data Security
Stratejik İşler implements appropriate technical and organisational measures in accordance with Article 12 of the KVKK and Article 32 of the GDPR to ensure a level of security appropriate to the risk, including encryption of data in transit and at rest, row-level access controls, regular security assessments, and incident response procedures. See the Security page for the full control list.
Standards we align to
These badges describe the frameworks we design our security and privacy program around. They are not, by themselves, a claim of independent certification — see per-badge status below.
- SOC 2 Type II standard: SOC 2 Type IIFramework · aligned
Controls mapped to the AICPA Trust Services Criteria for security, availability, and confidentiality.
- EU General Data Protection Regulation: GDPREU · in effect
Processing built around GDPR data-subject rights, lawful bases, and Article 32 security obligations.
- ISO/IEC 27001 information security standard: ISO/IEC 27001Framework · aligned
Information security controls aligned to the ISO/IEC 27001 Annex A control set.
11. Policy Changes
Stratejik İşler reserves the right to update this Privacy Policy to comply with changes in GDPR, Turkish and EU data protection legislation, or Platform services. Material changes will be communicated via email or in-app notification.
12. Contact & Data Protection
To exercise your rights regarding your personal data or for any questions:
Stratejik İşler
Stratejik İşler Data Protection Office — KVKK İrtibat Kişisi / Data Protection Contact
Abide-i Hürriyet Cd. No: 211/64, Şişli, İstanbul, Türkiye
E-mail (data protection & rights requests): privacy@hinetworking.com
General enquiries: info@hinetworking.com
Under the Turkish Communiqué on Application Procedures to the Data Controller, applications may be submitted in writing (wet-signed, delivered in person, via notary, or by registered post to the address above), through a registered electronic mail (KEP) address, with a secure electronic signature or mobile signature, from the e-mail address already registered in our systems, or through our online KVKK application form, which also provides a printable written application. We respond within 30 days.