Privacy notice
How Global Talent Journey uses personal data: what it can and cannot read, why, on what legal basis, who receives it, how long it is kept and how to use your rights under the UK GDPR, the EU GDPR and Turkish KVKK.
This page will be reviewed by a qualified lawyer before registration opens. Last updated .
Who is responsible for your data
- Operator
- Furkan Efe Genç
- Trade name
- Furkan Efe Genç
- Legal form
- sole proprietorship (şahıs işletmesi), self-employed professional (serbest meslek erbabı)
- Registration
- Self-employed professional (serbest meslek erbabı)
- Address
- Ahlatlıbel Mahallesi, 1859. Cadde No 44/32 (Stüdyo Kolej Binası), 06850 Çankaya/Ankara, Türkiye
- Telephone
- +90 531 835 00 80
- Tax office
- Doğanbey Vergi Dairesi
- Tax number
- 3920781168
- Brand
- Global Talent Journey
The operator named above is the controller of your personal data under the UK GDPR and the EU GDPR, and the veri sorumlusu under Turkish Law No. 6698 on the Protection of Personal Data (KVKK). Global Talent Journey (GTJ) is the brand of this business.
No representative in the United Kingdom or in the European Union has been appointed yet. The operator will name them here before accounts are offered to people in those countries. Registration is not open yet: today only test accounts and the owner’s own accounts exist.
Contact for anything on this page: hello@talentvisajourney.com or the contact form, which needs no sign-in.
GTJ intends to show this notice as a link on the sign-up page and in the app before an account is created, separately from any consent. It does not ask you to tick that you have read it.
What GTJ can and cannot read
GTJ cannot read the contents of your vault. That does not mean GTJ processes no personal data: the account around the vault, the community and the logs are ordinary personal data, listed here.
| Data | Can GTJ read it? | Why |
|---|---|---|
| Your e-mail address, username and name | Yes | Needed to run your account and send account e-mails. |
| IP addresses and usage logs held by the community engine | Yes | Kept by the engine for security and abuse prevention. |
| How many files you store, their encrypted sizes and upload times | Yes | Needed for storage limits, versions and deletion. |
| Community posts, comments, polls and reactions | Yes | They are written for other members to read and are not encrypted. |
| Reports, appeals and moderation decisions | Yes | Needed to run moderation and to tell you the outcome. |
| Contact requests to professionals and professional applications | Yes | They are delivered or reviewed by people, so they are not encrypted. |
| Requests sent through the contact form | Yes | The operator reads and answers them. |
| The contents and names of files in your vault | No | Encrypted on your device with a key the operator does not hold. |
| Your workspace (checklist, targets, notes) and private profile | No | Encrypted on your device before they are stored. |
The vault is not open for real sensitive documents yet. Its encryption is waiting for an independent security review; until then only test documents are stored. If you lose both your vault passphrase and your recovery key, nobody, including GTJ, can open your encrypted files.
What is processed, why, on what basis and for how long
Each activity below names the personal data, why it is used, the legal basis under the UK and EU GDPR, the ground under KVKK Art. 5, and how long it is kept. Where legitimate interests are used, GTJ has weighed them against your interests, and you can object (see your rights).
| Activity | Personal data | Purpose | UK GDPR / EU GDPR basis | KVKK ground (Art. 5(2)) | How long |
|---|---|---|---|---|---|
| Account | E-mail, username, name, password hash or passkey, sessions, IP at sign-in | Create and run your account | Contract, Art. 6(1)(b) | (c) necessary for the contract | While the account exists |
| Signing in with Google or Apple (not available yet) | Your e-mail address, your name and the account identifier the provider uses for you, received from that provider when you choose it. Nothing else reaches GTJ, and nothing of yours at GTJ reaches the provider | Create and run your account without you keeping a password with GTJ at all | Contract, Art. 6(1)(b) | (c) necessary for the contract | With the rest of the account, while the account exists |
| Vault storage | Encrypted files and keys; file count, encrypted sizes and times | Store your documents encrypted with a key GTJ does not hold | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you delete them; trash is emptied 7 to 8 days after you move a file there |
| Workspace and private profile | Encrypted records; revision and times | Your preparation checklist, targets and CV fields | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you delete them or the account |
| Community posting | Posts, titles, polls, reactions, labels, times | Let members share work, ask and give feedback | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you delete them; at account deletion you choose delete or anonymise |
| Community profile photo (not available yet) | An optional small photo you choose. Your device and the server each decode it and save it again as a new image, so location, camera details and the original file name are removed. It is stored under a random name in a separate storage bucket in EU jurisdiction and shown only to people who can see your community profile | Show other members who is posting | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you remove or replace it, or delete your account. A copy whose removal failed is deleted by a daily clean-up |
| Moderation, reports and appeals | Reports with reason and text, hidden or removed state, appeals, moderator’s reason, rules versions you accepted | Keep the community lawful and safe; tell reporters the outcome; hear appeals | Legitimate interests, Art. 6(1)(f), and legal obligations where online safety law applies | (ç) legal obligation where one applies, (e) establishing or defending a right, (f) legitimate interest | Acceptances and appeals: while the account exists. Reports: kept with the engine’s review record; a fixed period is still to be set |
| Professional applications and licence checks | Professional name, jurisdiction, register number, regulator link, firm, professional e-mail, scope, languages, check records | Check a professional’s registration before listing | Contract, Art. 6(1)(b); legitimate interests for re-checks and complaints | (c) contract, (f) legitimate interest | While the application or the account exists |
| Contact requests to a professional | The name, e-mail address and message you choose to share | Deliver your message to the one professional you chose | Contract, Art. 6(1)(b) | (c) necessary for the contract | Record: until account deletion. The e-mail copy the professional receives cannot be recalled or deleted by GTJ |
| Contact form without sign-in | Request type, e-mail, optional name, message, content link, good-faith statement, a keyed hash of your IP address | Answer questions, data-rights and deletion requests, illegal-content notices and complaints | Legal obligation, Art. 6(1)(c), for rights requests and notices; legitimate interests for other questions and abuse prevention | (ç) legal obligation (KVKK Art. 13), (f) legitimate interest | 12 months from receipt (a proposal checked by the lawyer) |
| Security and service logs | IP addresses, browser type, sign-in, search and page-view logs, staff actions | Protect accounts and investigate abuse | Legitimate interests, Art. 6(1)(f) | (ç) legal obligation where Law No. 5651 applies, (f) legitimate interest | No fixed period yet; your IP rows are cleared when your account is deleted |
| Backups | A daily copy of the engine database, kept in EU jurisdiction storage (no vault file contents) | Restore the service after a failure | Legitimate interests, Art. 6(1)(f) | (f) legitimate interest | One copy a day; the newest seven are kept, so a copy is deleted after about a week |
| Deletion records | Account number, a random reference of the deletion, creation and deletion time, and whether you chose to delete or anonymise your posts; no name, e-mail or content. A copy is kept in storage separate from the database | Stop a restored backup from bringing a deleted account back | Legitimate interests, Art. 6(1)(f) | (ç) KVKK Art. 7, (f) legitimate interest | As long as a backup older than the deletion can be restored |
| Reminders you set | A random reminder number and the time it is due. The words of the reminder stay encrypted in your workspace | Tell you when a reminder you set is due | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you delete it, and at the latest 30 days after its time; also removed when you reset your vault or delete your account |
| Push notifications on a phone (not available yet) | For each phone where you turn them on: the notification token of this app, the platform and the notification types you chose for that phone | Send a notification with neutral text to that phone | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you turn them off on that phone, sign out there, remove the device or delete your account |
| Account e-mails | Recipient address, name, e-mail content | Confirm your address, sign-in and password e-mails, notifications, delivering contact requests | Contract, Art. 6(1)(b) | (c) necessary for the contract | The sending provider’s log period has not been checked yet |
| This website and the contact address | Request data at the delivery network; sender, subject and content of e-mail you send | Serve these pages and forward your e-mail to the operator | Legitimate interests, Art. 6(1)(f) | (f) legitimate interest | E-mail routing logs 30 to 31 days at the provider; e-mails in the operator’s inbox while the request is handled |
How data is collected
- From you, by automated means: what you type and upload in the member app, on the sign-up page and in the contact form.
- Automatically, while you use the service: sign-in, security and usage logs recorded by the community engine.
- From other people: members may mention you in a post or report a post of yours; a professional’s registration details are checked against public registers.
- From Google or Apple, once signing in with them is offered and you choose it: your e-mail address, your name and the account identifier that provider uses for you. Signing in with Google or Apple is not available yet, so nothing reaches GTJ this way today.
Collection is automated in every case (KVKK Tebliğ Art. 5(1)(i)). No decision about you is made by automated means (see below).
Sensitive data in your documents
GTJ does not ask for health, religion, ethnic origin, political opinion, biometric data or criminal records. Documents you choose to keep in your vault, such as a passport, a medical certificate or a criminal-record certificate, can contain such data, and so can documents about other people (referees, employers, family). GTJ treats vault contents as possibly containing special-category data. They are encrypted on your device, the operator holds no key and cannot read them, and encryption is used as a safeguard, never as a reason to say no personal data is processed. Whether storing encrypted special-category data counts as processing it under KVKK Art. 6 and GDPR Art. 9 is one of the questions put to the lawyer.
Please do not upload documents about other people, or unnecessary pages about your family or children, unless your preparation really needs them.
Who receives data
Global Talent Journey works with 5 companies that receive personal data: 3 process it on the operator’s instructions, and 2 decide their own purposes and take their own responsibility for what they do. The “Role” column says which is which. None of them can read the contents of your vault.
| Provider | Role | What for | Personal data | Where | Transfer safeguard | Agreement status |
|---|---|---|---|---|---|---|
| Railway Corporation 548 Market St PMB 68956, San Francisco, California 94104, United States Provider’s terms (checked ) | Processor — handles this data on GTJ’s instructions | Hosting the community engine: the application servers, the database and the cache that hold accounts, community posts, moderation records, encrypted workspace and profile records, file metadata and server logs | Account data (e-mail address, username, name), community content, moderation and appeal records, professional applications and contact requests, IP addresses and usage logs, encrypted records the operator cannot read | EU West region (Amsterdam, Netherlands). Railway's own volume backups are not used; database backups are kept in Cloudflare R2 storage in the EU jurisdiction | EU–US Data Privacy Framework and its UK Extension (Railway listed as active), with the EU Standard Contractual Clauses and UK Addendum in Railway's DPA as fallback. KVKK standard contract: not signed | Railway's data processing agreement has not been signed yet (it is completed through Railway's signature form) |
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, United States Provider’s terms (checked ) | Processor — handles this data on GTJ’s instructions | Registration of the domain name, DNS, delivery of this website, storage of encrypted vault files, storage of the community engine's database backups and deletion records, forwarding of e-mail sent to the contact address, processing with a language model of a question a website visitor types into the assistant on this site, so that it can be answered from this site's own published pages, and — for a member who uses the Pro document assistant — processing the text of that member's own documents with a language model, to turn it into the numbers that make the document searchable and to write the answer | IP addresses and request data of website visitors; encrypted vault files the operator cannot read; daily copies of the community engine's database (account data, community content, moderation and professional records, logs with IP addresses, and the encrypted records), and deletion records holding an account number and times; the sender, recipient, subject and content of e-mail sent to the contact address; the question a website visitor types into the assistant on this site, together with passages from this site's own published pages; and, for a member who uses the Pro document assistant, the readable text of that member's own documents — the whole document once while it is being indexed, and then the excerpts a question retrieves together with the question itself. Cloudflare states in writing that it does not use customer content to train the models it offers or to improve its own or third-party services, unless it has the customer's explicit consent | Encrypted vault files, database backups and deletion records: EU jurisdiction storage. Website delivery, DNS, e-mail forwarding, the language model that answers a website visitor's typed question, and the language model that processes document text for the Pro document assistant: Cloudflare's global network. Both the visitor's question and the member's document text are passed through rather than stored by GTJ's own worker, but Cloudflare publishes no retention period for the prompts and responses it receives, so how long they are kept there is not stated anywhere GTJ has read | EU–US Data Privacy Framework and its UK Extension (Cloudflare listed as active; all three certifications read 'Active – Re-certification under Review' with usage end 15 September 2027, read from the Commerce Department API on 22 September 2026), with the EU Standard Contractual Clauses and UK Addendum in Cloudflare's DPA as fallback. KVKK standard contract: not signed | Cloudflare's data processing addendum (version 6.4) is part of its self-serve agreement; the date GTJ accepted it has not been recorded yet |
| Plus Five Five, Inc. (Resend) 2261 Market Street #5039, San Francisco, CA 94114, United States Provider’s terms (checked ) | Processor — handles this data on GTJ’s instructions | Sending account e-mails from the community engine: address confirmation, sign-in links, password resets, notifications and contact requests delivered to a professional | Recipient e-mail address and name, and the content of those e-mails (for a contact request to a professional: the name, e-mail address and message the member chose to share) | Sending region EU (Ireland). Resend's regions page states that all account data, including e-mail metadata, logs and API records, is stored in the United States whatever the sending region, and its agreement states that its primary processing takes place in the United States | EU Standard Contractual Clauses, UK Addendum and the EU–US Data Privacy Framework with its UK Extension, as named in Resend's DPA; Resend's framework listing not yet checked by GTJ. KVKK standard contract: not signed | Resend's data processing addendum takes effect when its terms are accepted; the GTJ sending domain is set up and the engine has sent through it since 13 September 2026, but the date GTJ accepted the terms has not been recorded |
| Google LLC (Sign in with Google) 1600 Amphitheatre Parkway, Mountain View, California 94043, United States Provider’s terms (checked ) | Independent controller — decides its own purposes; GTJ instructs it about nothing | Authenticating a member who chooses to sign in with a Google account, instead of an e-mail address and password | What Google returns to GTJ: the member's Google account identifier, e-mail address and name. What Google itself learns: that this Google account signed in to Global Talent Journey, and when, because the sign-in happens on Google's own page. GTJ sends Google no vault file, no workspace, no community content and no document | Not stated for this product. Google's privacy policy says only that it maintains servers around the world and that information may be processed on servers outside the country where the person lives | EU–US Data Privacy Framework, the Swiss–US Framework and the UK Extension: Google LLC is listed as Active on all three (the Data Privacy Framework list, read 19 September 2026), covering HR and non-HR data. No agreement between GTJ and Google covers this product; the agreement column says what was read. KVKK standard contract: not signed | None recorded. Google's API Terms of Service incorporate the Google Controller-Controller Data Protection Terms, under which each party 'is an independent controller', but those terms apply only to the services Google lists as covered — and Google's own list does not name Sign in with Google. The in-scope list of the Google Cloud Data Processing Addendum does not name it either. Both lists read 19 September 2026: Google states no role for this product on any page GTJ has read |
| Apple Inc. (Sign in with Apple) One Apple Park Way, Cupertino, California 95014, United States Provider’s terms (checked ) | Independent controller — decides its own purposes; GTJ instructs it about nothing | Authenticating a member who chooses to sign in with an Apple Account, instead of an e-mail address and password | What Apple returns to GTJ: an Apple account identifier, the name the member may edit before sharing it, an e-mail address which is a forwarding address generated by Apple if the member chooses to hide the real one, and a simple binary score Apple describes as giving the developer confidence that the member is a real person. What Apple itself learns: Apple's privacy page states that Apple does not track which apps or websites a person signs in to, or when. GTJ sends Apple no vault file, no workspace, no community content and no document | Not stated for this product. Apple's privacy policy says personal data collected worldwide is generally stored by Apple Inc. in the United States, and that personal data relating to individuals in the European Economic Area, the United Kingdom and Switzerland is controlled by Apple Distribution International Limited in Ireland | None recorded, and this row is the only one on this page in that position. Apple Inc. is not on the Data Privacy Framework list at all — not as an active participant and not as an inactive one (searched as 'Apple Inc.' and as 'Apple', 19 September 2026) — so the safeguard the other rows rely on does not exist here. Whether the Irish Apple entity named in Apple's own privacy policy answers the question for members in the European Economic Area and the United Kingdom is an open legal point, and it answers nothing for members in Türkiye. Owner item O-41. KVKK standard contract: not signed | None recorded. No data processing agreement for Sign in with Apple was found in the Apple Developer Program License Agreement (read 19 September 2026). Its Sign in with Apple clause sets out what the developer may not do with the data — not sell or share it with advertising platforms, data brokers or information resellers, and not try to re-identify a member who chose to stay anonymous — and states no role for Apple itself |
- A professional you choose receives the name, e-mail address and message you decide to share, by e-mail.
- Other members see what you post in the community. The community is not public and is not indexed by search engines.
- Authorities receive data only when a binding legal order requires it; the operator checks each order and, unless the law forbids it, tells the person concerned. Encrypted vault contents could only ever be handed over in encrypted form.
- Signing in with Google or Apple is not available yet. When it is and you choose one, that provider gives GTJ your e-mail address, your name and the account identifier it uses for you, and learns that you signed in to Global Talent Journey; it never receives your vault, your workspace or anything you post. It will be listed above before that happens. What each provider receives, in full.
- Push notifications are not available yet. When they are and you turn them on for a phone, Apple (iPhone) or Google (Android) delivers them: they receive that phone’s notification token and the neutral text, never the content of a reminder, a post or a document. They will be listed above before that happens.
- No data is sold, and none is used for advertising or to train artificial intelligence. No payment provider is used today.
Transfers outside Türkiye, the UK and the EU
The operator is in Türkiye and every service provider above is a company in the United States, so your data is transferred abroad. The servers GTJ chose are in the European Union where the provider allows it (Amsterdam for the engine, EU jurisdiction storage for vault files and database backups), but a provider can still access data from the United States.
- UK GDPR and EU GDPR: Railway and Cloudflare are listed as active under the EU–US Data Privacy Framework and its UK Extension; Resend’s agreement names the Framework too, but GTJ has not yet checked its listing. Each provider’s agreement adds the EU Standard Contractual Clauses and the UK Addendum, which apply if the Framework does not.
- KVKK: the Turkish Personal Data Protection Board has not declared any country adequate, so a transfer needs one of the safeguards in KVKK Art. 9, normally the Board’s standard contract notified within five business days. That standard contract has not been signed with any of the providers yet. The operator is asking them, and this is an open item that must be resolved before registration opens.
How long data is kept
Personal data is kept only as long as its purpose needs. The periods for each activity are in the table above. In short:
- Your account, vault, workspace, profile and community records stay until you delete them or your account. Deleting the account starts at once.
- Contact-form requests: 12 months from receipt.
- Security logs and reports do not have a fixed period yet. This is a known gap; the periods will be set and published here before registration opens.
- Database backups are taken once a day and the newest seven are kept, so a backup can still contain a deleted account for about a week; after any restore, deletions are applied again so a deleted account does not come back.
- Reminders: at the latest 30 days after their time.
- No billing records exist, because no payment is taken. If payments start, the periods the law sets for commercial records will be added here first.
Your rights
Under the UK GDPR and EU GDPR you can ask to:
- see the personal data GTJ holds about you and get a copy (access);
- correct data that is wrong or incomplete;
- have your data erased;
- restrict how it is used while a question is being settled;
- receive the data you gave in a structured, machine-readable form (portability: the in-app export does this);
- object to processing based on legitimate interests;
- withdraw consent where consent is used (GTJ does not rely on consent today).
Under KVKK Art. 11 you have the right to:
- learn whether your personal data is processed;
- request information if it has been processed;
- learn the purpose of processing and whether it is used in line with that purpose;
- know the third parties in Türkiye or abroad to whom it is transferred;
- ask for correction if it is incomplete or inaccurate;
- ask for deletion or destruction under the conditions of KVKK Art. 7;
- ask that the third parties it was transferred to are told of a correction, deletion or destruction;
- object to a result against you that arises only from automated analysis;
- claim compensation if you suffer damage because of unlawful processing.
How to use your rights
- In the app: My profile → Settings → Account and data → Download my data, or Delete my account.
- Without signing in: the contact form, choosing “Privacy and data rights” or “Account deletion”.
- By e-mail: hello@talentvisajourney.com
Exercising your rights is free. GTJ answers within one month under the GDPR and within 30 days under KVKK Art. 13, and tells you if a complex request needs longer and why. GTJ may ask you to confirm that the account is yours, for example by replying from the account’s e-mail address; it does not ask for identity documents for this.
Complaints
You can complain to GTJ first, through the contact form (type “Complaint” or “Privacy and data rights”) or by e-mail. GTJ acknowledges a complaint within 30 days and tells you the outcome. You can also complain to a supervisory authority at any time:
- Türkiye: the Personal Data Protection Board (kvkk.gov.tr). Under KVKK Art. 14 you first apply to GTJ, then complain within 30 days of GTJ’s answer, or within 60 days of your application if there is no answer.
- United Kingdom: the Information Commissioner’s Office (ico.org.uk).
- European Union: the data protection authority of the country where you live or work (list of authorities).
Automated decisions
GTJ makes no decision about you by automated means and does not profile you. The preparation percentage in the workspace only counts the tasks you marked done; it is not an assessment of your case. Posts can be hidden automatically when several members report them; a moderator then reviews them and you can appeal.
Minimum age
Accounts are for people aged 18 or over. GTJ does not ask for an identity document to check this. If you believe a person under 18 has an account, tell GTJ through the contact form and the account will be reviewed.
E-mails
GTJ sends no marketing e-mails. Account e-mails (address confirmation, sign-in, password, notifications you chose) are part of the service. If marketing messages are ever offered, they will need a separate, optional choice that is off by default.
Changes to this notice
Every change to this notice is dated at the top of the page. A change that affects what data is used or why is announced in the app and by e-mail before it takes effect, and a new purpose is described here before data is used for it. Continuing to use the service is never treated as agreeing to such a change.