OPEX AI WorkforceOPEX

Website Disclosure Notice (GDPR)

Last updated: 2026-08-24

Elektra Software Ltd. (operating under the OPEX brand), in its capacity as data controller under Turkish Law No. 6698 on the Protection of Personal Data ("KVK"), processes the personal data of those who visit our website and benefit from our services within the scope explained below.

Purpose and Scope

As Elektra Software Ltd. (hereinafter referred to as "Elektra" or the "company"), we would like to state that we work diligently to keep the personal data you share with us secure and protected. Elektra is a "data controller" in the situations set out in this text and in the Privacy Policy. We process your personal data in accordance with Law No. 6698 on the Protection of Personal Data ("KVK") and take proportionate and adequate administrative and technical measures to protect it.

Within this framework, the personal data of those who visit our website, benefit from our services, and of our business partners and customers, is processed under the conditions explained below and within the limits set out in the legislation. For more detailed information on how your personal data is processed, you may review our Privacy Policy, which forms part of our disclosure obligation.

We are not responsible for the data security measures provided by websites that do not belong to us and by the organisations that own those sites, even if we link to them from our website. We recommend that you review the data security policies of the relevant site and/or organisation.

Key Definitions

  • Explicit consent: Consent relating to a specific subject, based on information and expressed by free will.
  • Anonymisation: Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.
  • Data subject: The natural person whose personal data is processed.
  • Personal data: Any information relating to an identified or identifiable natural person.
  • Employee handling personal data: Employees who, as part of their job description, process the personal data of data subjects on behalf of the organisation.
  • Processing of personal data: Any operation performed on data, such as obtaining, recording, storing, retaining, altering, reorganising, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, by wholly or partly automated means, or by non-automated means provided that it forms part of a data recording system.
  • Committee: The internal committee formed within the organisation in accordance with the "Directive on the Duties and Responsibilities of the Personal Data Protection Committee", responsible for monitoring all personal data processes carried out by the organisation, its units and employees, checking compliance with the policies, and conducting personal data processes on behalf of the organisation.
  • Board: The Personal Data Protection Board.
  • Authority: The Personal Data Protection Authority.
  • KVK: Law No. 6698 on the Protection of Personal Data.
  • Special categories of personal data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
  • Data processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.
  • Data recording system: The recording system in which personal data is processed and structured according to specific criteria.
  • Data controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
  • Joint data controller: Another data controller with whom the organisation shares personal data within the scope of its commercial and corporate activities and jointly carries out processing activities on that data for the duration of such sharing.
  • Independent data controller: Another data controller with whom the organisation shares personal data on a one-off basis within the scope of its commercial and corporate activities.

3. Identity of the Data Controller

ELEKTRA SOFTWARE (the "Organisation") acts as "Data Controller" towards all natural persons it comes into contact with and whose personal data it processes while conducting its commercial activities — in particular employees, job candidates, customers, suppliers, supplier employees and visitors — and is obliged to fulfil the obligations arising from the law. ELEKTRA SOFTWARE fulfils these obligations through the administrative measures adopted by means of its compliance and control instruments, together with appropriate and proportionate technical measures.

ELEKTRA SOFTWARE processes your personal data in the capacity of "Data Controller" as defined in Article 3 of Law No. 6698 on the Protection of Personal Data. Its contact details are as follows:

  • Trade name: Elektra Software Ltd. (operating under the OPEX brand)
  • Address: 68 Tyrrells Way, Sutton Courtenay, Abingdon, OX14 4DH, London, England
  • Our web addresses: www.otelcrm.net, www.opexyurt.com, opex.app
  • Telephone: +90 534 273 39 30
  • E-mail: opex@opex.app

Legal Nature and Scope

Article 10 of Law No. 6698 imposes on data controllers the obligation to inform the persons whose personal data is processed. The disclosure obligation requires that you be informed about matters such as the rights listed in Article 11 of the KVK Law, the identity of the data controller, the purposes of processing personal data, the persons to whom it is transferred, the purposes and methods of transfer, the legal grounds for collecting personal data, and how you can apply as a data subject.

Through this "Disclosure Notice" and our "Privacy Policy", we as Elektra aim to inform you that your personal data is processed within the limits and conditions set out in the legislation.

Purposes of Processing Your Personal Data — Management Processes

Your personal data is processed for the following purposes, in line with the principles of the KVK Law:

  • Conducting commercial activities
  • Ensuring business continuity and providing legal and administrative business security
  • Planning and executing business and application strategies
  • Managing occupational health and safety processes
  • Presenting, promoting and providing information about the organisation, its services and products
  • Fulfilling obligations arising from legislation and contracts
  • Ensuring the physical security of the premises within and around the organisation
  • Obtaining legal support
  • Using electronic and other social media tools and printed, periodical and non-periodical publications
  • Conducting dealership processes
  • Establishing and maintaining communication with members of the press and with press and broadcasting organisations
  • Informing the public about our activities
  • Conducting business meetings in a timely and effective manner
  • Completing work in a timely and appropriate manner
  • Planning and conducting activities at local, national and international level
  • Maintaining relations with business partners and group companies in Türkiye and abroad
  • Conducting operations relating to intellectual and industrial property
  • Promoting, marketing and providing information about the organisation, its products and services
  • Obtaining feedback and responses from customers and potential customers
  • Providing technical support to customers
  • Answering questions from customers and potential customers
  • Providing support regarding electronic invoicing services
  • Participating in events such as trade fairs and seminars

Purposes of Processing Your Personal Data — IT Processes

Your personal data is processed for the following purposes within the scope of IT processes, and for these purposes we process it within the conditions for processing personal data set out in Articles 5 and 6 of the KVK Law:

  • Establishing and updating the IT and communication infrastructure
  • Managing the users of IT tools and systems
  • Managing corporate e-mail accounts
  • Managing, auditing and closing the e-mail accounts of former employees
  • Managing, monitoring and auditing portable and/or desktop electronic devices
  • Conducting operations relating to mobile application users
  • Conducting operations relating to website members
  • Ensuring data security and archiving data
  • Keeping internet access logs
  • Tracking the organisation's vehicles and their users
  • Protecting and managing customers' digital assets and rights

Methods of Processing Personal Data

We process your data in accordance with the principles listed in Article 4 of the Law and by obtaining your explicit consent. On the other hand, we may also process your personal data without "explicit consent" where one of the conditions listed in Article 5 of the Law exists, such as being expressly provided for by law, actual impossibility, processing directly related to the conclusion or performance of a contract, or being mandatory for the data controller to fulfil its legal obligation.

Data Collected on Our Website (www.opex.app)

On the www.opex.app marketing site, personal data is collected from visitors only through the contact form. The form includes your full name, e-mail address, telephone number, hotel name, number of rooms, the products you are interested in and your message; this data is processed on the legal grounds of "being directly related to the conclusion or performance of a contract" and "legitimate interest" under Article 5 of the KVK Law, so that your request can be assessed and answered, and is forwarded to our team at support@opex.app through our e-mail delivery service provider.

In order to prevent the form from being abused by automated software (bots), Cloudflare Turnstile bot verification is performed before submission; during this verification your IP address and technical verification data are transmitted to Cloudflare. This processing is based on our legitimate interest in ensuring data security.

No analytics or advertising cookies, pixels or tracking scripts are used on the site. All cookies and browser local storage entries used on the site are listed in our Cookie Policy.

To Whom and for Which Purposes Personal Data Is Transferred

As Elektra, we transfer the personal data we collect and process in accordance with the KVK Law — for the purposes of business continuity and the performance of services and accompanied by confidentiality agreements — to official institutions/organisations, to organisations in Türkiye and abroad with which we have a commercial or sectoral relationship, to organisations and services in Türkiye and abroad from which administrative and technical services are procured, to the organisation's solution partners, and to organisations in Türkiye and abroad acting as performance assistants.

In addition, data may be transferred abroad to companies providing the infrastructure and services we need for electronic communication channels, to companies providing cloud computing services offering a higher level of data security, and in order to benefit from the services offered by instant messaging or online communication tools that are widely used today. You can find detailed information about with whom and how we share data in our Privacy Policy.

8.1. Sharing of Your Personal Data Within Türkiye

Within the framework of the conditions for processing personal data set out in Article 8 of the KVK Law, your personal data is shared within Türkiye with the following parties:

  • Where necessary for the planning and performance of the commercial activities carried out by the organisation, with private institutions and organisations such as group companies, business partners, affiliates, consultancy firms and other service suppliers in Türkiye and abroad, as well as with public institutions and organisations
  • With natural and legal persons providing services in these fields, and the third parties they work with, for the purpose of ensuring business continuity, providing legal, technical and commercial business security, and planning and executing human resources, occupational health and safety and emergency processes and strategies
  • With the persons with whom the organisation has entered into contracts within the framework of the services it procures, and the third parties they work with
  • With suppliers providing external services in the nature of the services offered by the organisation or of socio-economic benefits to employees, and the third parties they work with
  • Where necessary for the organisation to fulfil its legal obligations, with our business partners, consultancy firms, suppliers, private institutions and organisations, courts, public institutions and organisations and competent authorities
  • With IT and archiving companies or cloud service suppliers in Türkiye and abroad, for the infrastructure and services required for corporate electronic communication channels and for ensuring data security
  • With platforms and applications originating abroad from which we procure services in order to use online communication channels and tools such as instant messaging, file sharing, video conferencing and e-mail

8.2. Sharing of Your Personal Data Abroad

Elektra shares data with suppliers in Türkiye and abroad in order to communicate effectively with the users and members of our websites and to improve the efficiency and appeal of the sites and meet visitor expectations. As a data controller, Elektra carries out the necessary checks as far as possible and obtains the necessary legal undertakings to ensure that such organisations and their services also fulfil the obligations set out in the Law. In this context, your personal data is shared:

  • With Microsoft, based in the USA, for office work and operations
  • With Facebook, based in the USA, through the WhatsApp application used as an instant messaging tool between employees and in relationships with customers for business purposes
  • With Google, WeTransfer and Microsoft, based in the USA, for sharing large files for business purposes
  • With Microsoft, based in the USA, through Azure, which provides data centre and cloud server services
  • With Ammy, based in the USA, and AnyDesk and TeamViewer, based in Germany, which provide remote access in order to give technical support to customers
  • With Microsoft, based in the USA, through the Skype application for video conferencing services
  • With Google, based in the USA, and Yandex, based in Russia, for our corporate e-mail services
  • With SparkPost (Bird), based in the USA, so that requests submitted through the www.opex.app contact form are delivered to our team by e-mail (delivery is carried out through servers located in the EU region)
  • With Apple, Microsoft and Google, based in the USA, which provide the mobile and desktop operating systems used to carry out daily business activities
  • With Facebook, Twitter, Instagram and LinkedIn, based in the USA, which provide social media services from abroad
  • With Cloudflare, based in the USA, within the scope of the Turnstile service used to protect the www.opex.app contact form against automated software (bots)

Privacy Policies of Service Providers

You can access the privacy policy of each service provider through the links below:

  • Microsoft: https://privacy.microsoft.com/en-us/privacystatement
  • WhatsApp: https://www.whatsapp.com/legal/client
  • Google: https://policies.google.com/privacy?hl=en-US
  • WeTransfer: https://wetransfer.com/legal/privacy
  • Constant Contact: https://www.endurance.com/privacy/privacy
  • Ammy: https://www.ammyy.com/en/priv_policy.html
  • AnyDesk: https://anydesk.com/en/privacy
  • TeamViewer: https://www.teamviewer.com/en/privacy-policy/
  • Skype: https://support.skype.com/en/skype/all/privacy-security/
  • Yandex: https://yandex.com.tr/support/legal/confidential/01032016/index.html?lang=en
  • SparkPost (Bird): https://bird.com/legal/privacy-statement
  • Apple: https://www.apple.com/legal/privacy/en-ww/
  • Facebook: https://www.facebook.com/policy.php
  • Twitter: https://twitter.com/en/privacy
  • Instagram: https://help.instagram.com/519522125107875
  • LinkedIn: https://www.linkedin.com/legal/privacy-policy
  • Cloudflare: https://www.cloudflare.com/privacypolicy/

By Which Methods We Collect Your Personal Data

Although it may vary depending on the service, product or commercial activity provided by our company, your personal data may be collected and processed by updating it — verbally, in writing or electronically, by automated or non-automated means, through offices, the website, social media channels, mobile applications and similar means in Türkiye and abroad — in accordance with Articles 4, 5 and 6 of the KVK Law.

How Do We Protect Your Personal Data?

All necessary technical and administrative measures are taken to protect the personal data collected by Elektra, to prevent it from falling into the hands of unauthorised persons, and to ensure that our customers and prospective customers are not harmed. In this context, we take care that the software we use complies with the applicable standards, that data transfer agreements are signed with the data processors and third parties with whom data is shared, and that our Privacy Policy is observed within the company.

Your Rights as a Data Subject

As data subjects, you have the following rights as listed in Article 11 of the KVK Law:

  • a) To learn whether your personal data is being processed
  • b) To request information if your personal data has been processed
  • c) To learn the purpose of processing personal data and whether it is used in accordance with that purpose
  • d) To know the third parties to whom personal data is transferred in Türkiye or abroad
  • e) To request rectification of personal data that has been processed incompletely or inaccurately, and to request that the operation carried out in this respect be notified to the third parties to whom the personal data has been transferred
  • f) To request erasure or destruction of personal data where the reasons requiring its processing have ceased to exist, even though it has been processed in accordance with the KVK Law and other applicable legislation, and to request that the operation carried out in this respect be notified to the third parties to whom the personal data has been transferred
  • g) To object to an adverse outcome concerning the person arising from the analysis of the processed data exclusively by automated systems
  • h) To claim compensation for damage suffered as a result of the unlawful processing of personal data

How Can You Apply?

You can obtain detailed information from our organisation by downloading the "Data Subject Application Form" relating to your rights under Article 11 of the Law, which governs the rights of the data subject, and to the method of application. How applications concerning personal data are to be made is explained in detail in the "Disclosure Text for Personal Data Subject Applications" attached to that form. For the Application Form, which will make it easier for you to exercise your rights as a data subject, and for detailed information on other matters, you may review our Privacy Policy.

Language of This Text

This is an English translation provided for convenience. In case of any discrepancy between the Turkish and English versions, the Turkish version prevails.