Contact Form Privacy Notice
Last updated: 04.10.2026
This notice explains how the personal data you submit through the contact form on riskopto.com is processed, in accordance with Article 10 of the Turkish Personal Data Protection Law No. 6698 (the “Law”). Applications for the Business Partner Assessment service are covered by the separate privacy notice in the assessment panel.
Data controller
GRC Yönetim Bilişim Yazılım ve Danışmanlık Hizmetleri A.Ş. (“GRC Management”), Istanbul University Entertech Technopark, Avcılar / Istanbul, Türkiye. RiskOpto is a product of GRC Management.
Contact: info@grcmngmnt.com
What personal data is processed?
- Your name, email address and, optionally, your telephone number
- The content of your message and any other information you choose to share
- Your IP address at the time of submission, to prevent misuse (held only temporarily in server memory)
Please do not include special categories of personal data (e.g. health, religion, criminal convictions) in your message.
For what purposes and on what legal basis is it processed?
Your data is processed to respond to your request, to provide information and proposals about the product or service you ask about, and to prevent misuse of the form.
The legal bases are that processing is directly related to the conclusion of a contract (Article 5/2(c) of the Law) and the legitimate interests of the data controller, provided that your fundamental rights and freedoms are not harmed (Article 5/2(f)). Your data is not used to send marketing messages without your explicit consent.
How is it collected?
Data is collected electronically when you fill in the contact form and is forwarded by email to GRC Management's sales and contact team.
Who is it shared with?
Your data is seen only by GRC Management staff. To deliver the form, it may be transferred to Resend, our email delivery provider (sending infrastructure in Ireland), and to the email service provider where emails are stored, and, upon request, to authorised public authorities.
As some of these providers are located abroad, transfers abroad are made in accordance with Article 9 of the Law.
How long is it kept?
Contact correspondence is kept for 2 years after your request is closed. If the correspondence leads to a contract, the related records are kept for the duration of the contract and the statutory retention periods. At the end of the period, the data is deleted, destroyed or anonymised.
Your rights
Under Article 11 of the Law, you have the right to apply to the data controller to:
- learn whether your personal data is processed and, if so, request information about it,
- learn the purpose of processing and whether it is used in line with that purpose,
- know the third parties in Türkiye or abroad to whom it is transferred,
- request correction if it is incomplete or inaccurate, request deletion or destruction under Article 7 of the Law, and request that these actions be notified to third parties to whom it was transferred,
- object to a result against you arising from analysis exclusively by automated systems,
- claim compensation for damage arising from unlawful processing.
You can send your requests by email to info@grcmngmnt.com or in writing to the address above. Requests are answered free of charge within 30 days at the latest.