This notice explains how your personal data is processed in the Business Partner Assessment services (customer, dealer and distributor, franchise candidate and supplier assessment) provided through the RiskOpto Assessment Panel, in accordance with Article 10 of the Turkish Personal Data Protection Law No. 6698 (the “Law”).
Data controller
GRC Yönetim Bilişim Yazılım ve Danışmanlık Hizmetleri A.Ş. (“GRC Management”), Istanbul University Entertech Technopark, Avcılar / Istanbul, Türkiye. RiskOpto is a product of GRC Management.
Contact: sales@grcmngmnt.com
What personal data is processed?
- The applicant and representatives of the requesting company: name, title, company, email, telephone; contents of the application, proposal and correspondence.
- Representatives of the assessed business (the candidate): name, title and contact details; commercial, financial and operational information about the business; answers given and documents uploaded in the panel, and personal data contained in those documents (e.g. shareholder and director details).
- If the franchise candidate is an individual: financial information they declare, such as investment capacity, experience and sources of financing.
- Panel users: account details, an irreversible hash of the password (the password itself is not stored), language preference and records of actions such as sign-ins, document downloads and approvals.
- Security records: an irreversible hash of the IP address (raw IP addresses are not stored) and failed sign-in attempts.
The service does not request special categories of personal data listed in Article 6 of the Law (e.g. health, religion, criminal convictions). If documents contain such data or national ID numbers, please black them out before uploading.
For what purposes is it processed?
- Receiving the application, defining the scope and preparing a proposal
- Concluding and performing the service agreement
- Collecting and reviewing information and documents and preparing the assessment report
- Delivering the report to the requesting company and enabling its authenticity to be verified
- Managing panel accounts, ensuring information security and preventing misuse
- Complying with legal obligations and protecting rights in potential disputes
Legal grounds
Personal data is processed on the following grounds under Article 5(2) of the Law: it is directly related to the conclusion or performance of a contract (c), it is necessary for compliance with a legal obligation of the data controller (ç), it is necessary for the establishment, exercise or protection of a right (e), and it is necessary for the legitimate interests of the data controller, provided that this does not harm the fundamental rights and freedoms of the data subject (f). Where none of these grounds applies, explicit consent is obtained.
How is it collected?
Data is collected electronically through the application form, answers and documents provided in the panel, and email correspondence. Information about the assessed business is provided by the requesting company, or by the business itself at the requesting company’s direction.
Informing the assessed business
When applying, the company providing information about the assessed business declares that it is authorised to share that information and that it has informed the business about the assessment. A business invited to provide information through the panel is also given a separate information note. GRC Management uses this information only for the relevant assessment file.
Related document: Information Note for Assessed Businesses
How is the assessment carried out?
Answers are first evaluated by a scoring model based on GRC Management’s methodology. The result is reviewed by a GRC expert and approved by a separate approver; the report is not produced solely by automated processing. The report is an expert opinion based on the information provided and the report date.
Uploaded documents may undergo an AI-assisted pre-review to speed up the GRC team’s work (whether the document is the one requested, its legibility and its consistency with the answers). Documents that are clearly in order may be accepted through this pre-review; correction requests, the score and the report are always reviewed and approved by the GRC team. AI output alone never leads to an outcome against you.
Who is it shared with?
The assessment report is delivered only to the company that requested it. The requesting company does not see the answers or documents the assessed business provides in the panel; only the GRC team reviews them.
Where a supplier requests the report about itself (Supplier Onboarding Assessment), the report is delivered to the supplier, which shares it with its buyers itself.
Anyone who knows the verification code of an approved report can see, on the public verification page, only the file number, the name of the assessed business, the type of assessment, the report version, the approval date and the validity status; the class and content of the report are not shown.
To the extent necessary to provide the service, personal data may be transferred to the following service providers, and to competent public authorities upon request:
- Application hosting: Vercel Inc. (USA)
- Database: Neon (servers in Frankfurt, Germany)
- Document storage: Cloudflare R2 (data centres within the European Union)
- Email delivery: Resend (sending infrastructure in Ireland)
- AI-assisted document pre-review: Alibaba Cloud Model Studio (Frankfurt, Germany region)
As some of these providers are located outside Türkiye, transfers abroad are carried out in accordance with Article 9 of the Law.
How long is it kept?
Data in an assessment file is kept for 3 years from the closing of the file (delivery of the report, or the application not proceeding). At the end of this period it is deleted, destroyed or anonymised. Records that must be kept by law, such as invoices, are retained for the period required by the relevant legislation.
Security
Panel accounts are opened by invitation only. Connections are encrypted; documents are kept in private storage and opened only for authorised users through short-lived links. Actions such as document downloads and approvals are logged.
Your rights
Under Article 11 of the Law, you may apply to the data controller to:
- learn whether your personal data is processed,
- request information about such processing,
- learn the purpose of processing and whether data is used accordingly,
- know the third parties to whom data is transferred in Türkiye or abroad,
- request rectification of incomplete or inaccurate data,
- request erasure or destruction under the conditions of Article 7 of the Law,
- request that rectification, erasure or destruction be notified to third parties to whom data was transferred,
- object to an outcome against you arising exclusively from analysis by automated systems,
- claim compensation for damage arising from unlawful processing.
You can send your requests by email to sales@grcmngmnt.com or in writing to the address above. Requests are answered free of charge within 30 days at the latest. Where the EU General Data Protection Regulation (GDPR) applies to the processing of your data, you may also exercise the rights it grants you by contacting us at the same address.