Privacy Policy
This Privacy Policy explains how BriqMind processes, protects, and manages personal data collected when you use our digital products and services. BriqMind takes user privacy seriously and is committed to protecting personal data in accordance with applicable data protection laws, including KVKK and, where applicable, GDPR.
1. Scope
This policy applies to personal data collected through briqmind.com, its subdomains, related API services, integrations, customer service, and technical support channels. Third-party service providers may have their own privacy policies.
- Web platform: briqmind.com and related pages
- APIs and integrations, including form processing and email services
- Customer service and technical support communication channels
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Special Categories of Personal Data: Data such as race, ethnicity, political opinion, health, biometric data, and similar sensitive information.
- Data Controller: The person or entity determining the purposes and means of processing personal data (BriqMind).
- Data Processor: A third party processing personal data on behalf of the controller.
- Explicit Consent: Freely given, specific, and informed consent for a defined processing activity.
3. Data Controller
Data controller: BriqMind - Technology and Consulting Inc.
Contact: info@briqmind.com.
Address: Atac 2 Sokak, No: 66, Floor: 2, Apartment: 10, Cankaya, Ankara, Turkey.
4. Categories of Data Collected
- Identity Data: Name, surname, and, where applicable, username.
- Contact Data: Email, phone number, and company name.
- Transaction and Session Data: IP address, browser and device information, operating system, timestamps, and referring page.
- Behavioral Data: Page views, clicks, interaction records, feature usage, and search history.
- Identifier Data (Cookies): Session management, preference storage, and performance measurement.
- Content Data: Forms, files, messages, and attachments you submit to the platform.
5. Collection Methods and Sources
- Directly from you: Forms, email, support requests, and contract processes.
- Automatically: Cookies, browser/device records, and security logs.
- From third parties: Integrated services, only to the extent necessary.
6. Purposes of Processing
- Responding to user requests and managing support and customer relationships.
- Providing, maintaining, improving, and personalizing our services.
- Maintaining system security and preventing fraud or abuse.
- Performing analytics and reporting on performance, usage, and trends.
- Complying with legal obligations and responding to authorized requests.
- Sending marketing and announcement communications where you have consented.
- Testing and optimizing AI models using anonymized or pseudonymized data where possible.
7. Legal Bases
Your personal data may be processed on one or more of the following legal bases:
- Explicit consent
- Necessity for contract formation or performance
- Legal obligation
- Legitimate interests, provided your fundamental rights and freedoms are not harmed
- Establishment, exercise, or protection of legal claims
9. Third-Party Transfers and Processors
Your personal data may be transferred only for the purposes described in this policy and only to the extent necessary to the following recipient groups:
- Hosting/CDN and infrastructure providers: Hosting, content delivery, and firewall services.
- Communication and form services: Email delivery and contact form transmission.
- Analytics/logging services: Performance, security, and usage statistics.
- Authorized public institutions: Where required by law or valid administrative/judicial requests.
We do not sell your data. Processing by vendors is governed by contracts and appropriate technical and administrative safeguards.
- Hosting/CDN: Cloudflare
- Form submission: Formspree
- Font/asset delivery: Google Fonts, which may process technical data such as IP and user-agent when requested
10. International Data Transfers
Depending on server or vendor locations, personal data may be transferred outside Turkey. In such cases, appropriate safeguards such as adequacy decisions, binding corporate rules, standard contractual clauses, or mechanisms recognized under KVKK may be used, and explicit consent may be obtained where required.
11. Retention Periods
Data is retained only for the purposes of processing and for the periods required by applicable law. When the period expires, data is securely deleted, destroyed, or anonymized.
| Data Category | Examples | Retention Period | Legal Basis |
|---|---|---|---|
| Contact/Form | Name, surname, email, message | 3 years after request completion, longer where needed for limitation periods | Contract / legitimate interest |
| Session/Log | IP, timestamp, user-agent | 2 years for security and legal obligations, subject to updates | Legal obligation / legitimate interest |
| Analytics | Page views, interactions | 12-24 months, depending on tool settings | Consent / legitimate interest |
| Marketing | Newsletter consent, opens, clicks | Until consent is withdrawn or after 2 years of inactivity | Explicit consent |
12. Security Measures
- Appropriate encryption and transport security (HTTPS/TLS)
- Access control, authorization, and authentication procedures
- Least privilege principles and logging/monitoring
- Regular security updates and vulnerability testing
- Contractual and technical safeguards with processors
If a personal data breach is suspected, an impact assessment is performed and, where required, affected persons and authorities are notified.
13. AI, Profiling, and Automated Decisions
When developing our AI systems, we use anonymized or pseudonymized data wherever possible. Decisions that produce legal or similarly significant effects on you are not made solely by automated processing. Profiling-based marketing is conducted only with your consent and you may opt out at any time.
14. Your Rights (KVKK Art. 11 and GDPR Where Applicable)
- Learn whether your data is processed and request information
- Learn whether data is processed for its purpose and whether it is transferred domestically or abroad
- Request correction of incomplete or inaccurate data
- Request deletion or destruction where legal conditions apply
- Request restriction of processing or object to processing
- Object to automated processing or profiling
- Withdraw explicit consent at any time
- Request data portability where GDPR applies
- Lodge a complaint with the relevant supervisory authority
15. Application Method (Data Subject Requests)
You can submit requests regarding your rights to info@briqmind.com. You must provide the information required for identity verification and clearly state your request. Applications are generally concluded within 30 days.
16. Children's Privacy
Our services are not directed to persons under 18. We do not knowingly collect data from persons under 18. If we become aware of such processing, the relevant data will be deleted within a reasonable period.
17. Third-Party Sites
Our site may contain links to third-party sites or services. We are not responsible for their content or privacy practices and recommend reviewing their policies.
18. Policy Updates
This policy may be revised from time to time due to technological developments, changes in our business processes, or legal updates. The current version is always published on this page and the "Last Updated" date is shown above.
19. Effective Date and Version
This policy becomes effective on the date it is published. Previous versions may be shared upon request.
20. Contact
- Email: destek@briqmind.com
- Personal Data Requests: kvkk@briqmind.com
- Phone: +90 312 212 60 13
- Web: www.briqmind.com
BriqMind diligently fulfills its legal responsibilities regarding the security and privacy of user and customer data. This policy has been prepared in line with BriqMind's ethical values.