OPEX AI WorkforceOPEX

Privacy Policy

Last updated: 2026-08-24

Elektra Software Ltd. ("ELEKTRA", the "Company"), acting under the OPEX brand, provides the following disclosure regarding the personal data it processes through its web-based software, desktop software, websites and mobile applications, pursuant to Turkish Law No. 6698 on the Protection of Personal Data ("KVKK").

1. Purpose and Scope

As Elektra Software Ltd. ("ELEKTRA", the "Company"), we attach great importance to the protection of your personal data and private information. For this reason, in our capacity as Data Controller, we exercise all due care and diligence to ensure that your personal data is processed in accordance with Law No. 6698 on the Protection of Personal Data (the "KVK Law") — used, recorded, stored, updated, transferred and/or classified within the framework described below and in connection with our business purposes.

In this context, our Company takes all technical and administrative measures aimed at providing an appropriate level of security, in order to prevent the unlawful processing of and unlawful access to your personal data and to ensure its safekeeping, in line with the laws and regulations enacted to protect fundamental rights and freedoms — in particular the privacy of private life — and personal data.

The audience of this text is all natural persons whose personal data is processed on our websites and in our corporate processes, together with our employees. As Elektra Software (operating under the OPEX brand), we provide services through our online software delivered on a web and cloud basis ("Web-Based Software"), our desktop software ("Desktop"), our websites ("Site", "Sites") and our mobile applications ("Mobile Application", "Mobile Applications"). This disclosure covers all of the said software, sites and applications.

Our Web-Based Software: OPEX

Our Websites: www.otelcrm.net, www.opex.app, www.opexyurt.com

Our Mobile Applications: Opex Mobile, Opex Student Application

Personal information processed on our software, applications, sites and mobile applications is processed in accordance with the legislation on the protection of personal data. With respect to our web-based, desktop and mobile applications, we act as "data controller" only for those who create a user account and/or download the mobile applications and for those who use our websites, and this Privacy Policy applies only to the processing of data belonging to such persons.

Our customers who process and record data using our web-based, desktop and mobile applications are data controllers in their own right, independently of us. In such cases, as the Company we act only as a "data processor"; we therefore recommend that you consult the privacy policies, disclosure texts and similar documents of our customers who process your personal data where relevant.

We do not provide any warranty as to the data security and data protection practices and policies of third-party websites linked from our sites. We recommend that you separately review the data security and data protection policies of the relevant data controller.

3. Identity of the Data Controller

ELEKTRA SOFTWARE (the "Organisation") acts as "Data Controller" towards all natural persons it comes into contact with and whose personal data it processes while conducting its commercial activities — in particular employees, job candidates, customers, suppliers, supplier employees and visitors — and is obliged to fulfil the obligations arising from the law. ELEKTRA SOFTWARE fulfils these obligations through the administrative measures adopted by means of its compliance and control instruments, together with appropriate and proportionate technical measures.

ELEKTRA SOFTWARE processes your personal data in the capacity of "Data Controller" as defined in Article 3 of Law No. 6698 on the Protection of Personal Data. Its contact details are as follows:

  • Trade name: Elektra Software Ltd. (operating under the OPEX brand)
  • Address: 68 Tyrrells Way, Sutton Courtenay, Abingdon, OX14 4DH, London, England
  • Our web addresses: www.otelcrm.net, www.opex.app, www.opexyurt.com
  • Telephone: +90 534 273 39 30
  • E-mail: opex@opex.app

4. Key Definitions

The key terms used in this Privacy Policy have the following meanings:

  • Explicit consent: Consent relating to a specific subject, based on information and expressed by free will.
  • Anonymisation: Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.
  • Data subject: The natural person whose personal data is processed.
  • Personal data: Any information relating to an identified or identifiable natural person.
  • Employee handling personal data: Employees who, as part of their job description, process the personal data of data subjects on behalf of the organisation.
  • Processing of personal data: Any operation performed on data, such as obtaining, recording, storing, retaining, altering, reorganising, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, by wholly or partly automated means, or by non-automated means provided that it forms part of a data recording system.
  • Committee: The internal committee formed within the organisation in accordance with the "Directive on the Duties and Responsibilities of the Personal Data Protection Committee", responsible for monitoring all personal data processes carried out by the organisation, its units and employees, checking compliance with the policies, and conducting personal data processes on behalf of the organisation.
  • Board: The Personal Data Protection Board.
  • Authority: The Personal Data Protection Authority.
  • KVK: Law No. 6698 on the Protection of Personal Data.
  • Special categories of personal data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
  • Data processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.
  • Data recording system: The recording system in which personal data is processed and structured according to specific criteria.
  • Data controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
  • Joint data controller: Another data controller with whom the organisation shares personal data within the scope of its commercial and corporate activities and jointly carries out processing activities on that data for the duration of such sharing.
  • Independent data controller: Another data controller with whom the organisation shares personal data on a one-off basis within the scope of its commercial and corporate activities.

5. Purposes of Processing — Management Processes

Within our organisation, the personal data of data subjects is processed for the purposes set out below, entirely and directly in connection with the organisation's activities and with the commercial, business or legal relationship with the data subject:

  • Conducting commercial activities
  • Ensuring business continuity and providing legal and administrative business security
  • Planning and executing business and application strategies
  • Managing occupational health and safety processes
  • Presenting, promoting and providing information about the organisation, its services and products
  • Fulfilling obligations arising from legislation and contracts
  • Ensuring the physical security of the premises within and around the organisation
  • Obtaining legal support
  • Using electronic and other social media tools and printed, periodical and non-periodical publications
  • Conducting dealership processes
  • Establishing and maintaining communication with members of the press and with press and broadcasting organisations
  • Informing the public about our activities
  • Conducting business meetings in a timely and effective manner
  • Completing work in a timely and appropriate manner
  • Planning and conducting activities at local, national and international level
  • Maintaining relations with business partners and group companies in Türkiye and abroad
  • Conducting operations relating to intellectual and industrial property
  • Promoting, marketing and providing information about the organisation, its products and services
  • Obtaining feedback and responses from customers and potential customers
  • Providing technical support to customers
  • Answering questions from customers and potential customers
  • Providing support regarding electronic invoicing services
  • Participating in events such as trade fairs and seminars

5. Purposes of Processing — Employee-Related Purposes

The personal data of our employees is additionally processed for the following purposes:

  • Establishing and performing employment contracts
  • Delivering and implementing the services offered to employees
  • Providing socio-economic benefits to employees
  • Conducting processes relating to domestic and international assignments, travel and accommodation
  • Planning and conducting human resources processes
  • Recruitment, management of the employment relationship and performance evaluation processes
  • Creating personnel files and storing them in physical and electronic environments
  • Working-time tracking
  • Conducting exit procedures and exit interviews
  • Conducting performance and audit activities

5. Purposes of Processing — IT Processes

Within our organisation, personal data is processed for the following purposes as part of IT processes:

  • Establishing and updating the IT and communication infrastructure
  • Managing the users of IT tools and systems
  • Managing corporate e-mail accounts
  • Managing corporate social media accounts
  • Managing, auditing and closing the e-mail accounts of former employees
  • Managing, monitoring and auditing portable and/or desktop electronic devices
  • Conducting operations relating to mobile application users
  • Conducting operations relating to website members
  • Ensuring data security and archiving data
  • Keeping internet access logs
  • Tracking the organisation's vehicles and their users
  • Protecting and managing customers' digital assets and rights

6. Data Subjects Whose Personal Data Is Processed

ELEKTRA SOFTWARE generally and predominantly processes the data of data subjects within the scope of this Privacy Policy and other administrative and technical measures. The organisation's data processing policies, and in particular this Privacy Policy, will also be complied with when processing the personal data of natural persons outside these categories.

The categories of natural persons whose personal data is processed are as follows:

  • Employees
  • Employees working under indefinite-term employment contracts
  • Interns and participants in İŞKUR on-the-job training programmes
  • Job applicants
  • Customer representatives and employees
  • Supplier representatives and employees
  • Consultants and auditors
  • Public officials
  • Our visitors
  • Visitors to our websites
  • Potential customers and users
  • Our dealers

7.1. Personal Data of Our Employees, Employees Working Under Indefinite-Term Contracts and Interns

The organisation processes the personal data of employees, job candidates and interns in accordance with the employment contract and with laws, regulations and communiqués such as Labour Law No. 4857, the Turkish Code of Obligations No. 6098, the Social Insurance and General Health Insurance Law No. 5510, the Occupational Health and Safety Law No. 6331, the Individual Pension Savings and Investment System Law No. 4632, the Enforcement and Bankruptcy Law No. 2004, Law No. 4904 on Certain Regulations Concerning the Turkish Employment Agency, the Vocational Training Law No. 3308, the Turkish Commercial Code No. 6102, the Electronic Signature Law No. 5070, Law No. 5651 on the Regulation of Publications Made on the Internet and Combating Crimes Committed by Means of Such Publications, the Social Insurance Transactions Regulation, the Identity Notification Law No. 1774 and the Regulation on the Payment of Wages, Premiums, Bonuses and All Similar Entitlements Through Banks.

In this context, the organisation processes employees' personal data in the categories of identity, contact, personnel file, finance, professional experience, physical premises security, legal transactions, transaction security, risk management, visual and audio recordings and other information, as well as special categories of data such as belief, association membership, foundation membership, health information, criminal convictions and security measures.

7.2. Personal Data of Job Applicants

We process personal data such as identity, personnel file, contact, family information, finance, education, professional experience and habits, which job applicants share with us of their own volition through means such as a CV or cover letter, or which is shared with us by online employment platforms and/or talent agencies to which they have submitted their details for sharing with all relevant organisations, as well as special categories of data such as association and foundation memberships that they likewise record in their CVs of their own volition.

7.3. Personal Data of Representatives of Our Customers and Suppliers

The organisation processes the personal data of the natural person customers and suppliers with whom it establishes relationships while conducting its commercial activities, and of the representatives and natural persons of corporate customers and suppliers, pursuant to the service agreement and to laws, regulations and communiqués such as the Turkish Code of Obligations No. 6098, the Enforcement and Bankruptcy Law No. 2004, the Turkish Commercial Code No. 6102, the Tax Procedure Law No. 213 and the General Communiqués of the Tax Procedure Law. The organisation processes the personal data of such natural person customers, suppliers and representatives in the categories of identity, contact, finance, legal transactions and other information.

7.4. Personal Data of Auditors, Consultants and Public Officials

In order to conduct its commercial and production activities and to ensure their sustainability and quality, the organisation processes the personal data of auditors, consultants and public officials carrying out control and audit duties in accordance with laws, regulations and communiqués such as the Turkish Commercial Code No. 6102, the Customs Law No. 4458, the Tax Procedure Law No. 213, Labour Law No. 4857, Law No. 4904 on Certain Regulations Concerning the Turkish Employment Agency, the Social Insurance and General Health Insurance Law No. 5510 and the General Communiqués of the Tax Procedure Law.

In this context, the organisation processes the personal data of auditors, consultants and public officials in the categories of identity, contact and personnel file.

7.5. Personal Data of Our Application and Site Users

We process the personal data of users who use our own web-based, desktop and mobile applications, whether on their own behalf or on behalf of an organisation, in the categories of identity, personnel file, contact and location.

In addition, a trial account is created for persons who wish to try our applications and software, and their personal data in the categories of identity, personnel file and contact is processed.

7.6. Personal Data of Our Visitors

In order to ensure IT and facility security, we process visitors' personal data within the scope of Law No. 5651 on the Regulation of Publications Made on the Internet and Combating Crimes Committed by Means of Such Publications and on the basis of our legitimate interest.

In this context, visitors' personal data in categories such as identity, transaction security and physical premises security is processed.

7.7. Personal Data of Site Visitors and Members

On the basis of our legitimate interest, your personal data in categories such as transaction security and identity, belonging to users who visit our websites and register as members, is processed through forms and "cookies". For more information about cookies, please refer to our "Cookie Policy".

On the www.opex.app marketing site, data is collected from visitors only through the contact form. The form includes your full name, e-mail address, telephone number, hotel name, number of rooms, the products you are interested in and your message; this information is forwarded to our team at support@opex.app through our e-mail delivery service provider so that your request can be assessed and answered.

In order to prevent the form from being abused by automated software (bots), Cloudflare Turnstile bot verification is performed before submission, and during this verification your IP address and technical verification data are transmitted to Cloudflare.

7.8. Personal Data of Our Potential Customers

Aside from advertisements on our sites, we may inform our users, trial users, customers and potential customers about new products or services by e-mail, social media or telephone, having obtained their consent. Data subjects may object to such promotional, advertising and marketing communications at any time. Those who do not wish to receive such e-mails and SMS messages may block the messages, use the opt-out option, or contact us to request removal from the lists.

We also operate a newsletter to inform those interested in our products and/or services. Every newsletter contains a link allowing you to unsubscribe. Those wishing to unsubscribe may also do so through their account settings. Limited to this scope, we process the personal data of our potential customers in the categories of identity, personnel file and contact.

7.9. Personal Data of Our Dealers

The organisation processes the identity, contact and personnel file data of the representatives of our dealers involved in the sale, marketing and after-sales support of our products and services pursuant to the dealership agreement and to laws, regulations and communiqués such as the Turkish Code of Obligations No. 6098, the Enforcement and Bankruptcy Law No. 2004, the Turkish Commercial Code No. 6102, the Tax Procedure Law No. 213 and the General Communiqués of the Tax Procedure Law.

8. Rights of the Data Subject

The organisation acknowledges that, under the Law, the data subject has the right to give consent before their data is processed and, once it has been processed, to determine the fate of their data. In this sense, data subjects may exercise the following rights by applying to the Contact Person:

  • a) To learn whether their personal data is being processed
  • b) To request information if their personal data has been processed
  • c) To learn the purpose of processing their personal data and whether it is used in accordance with that purpose
  • ç) To know the third parties to whom personal data is transferred in Türkiye or abroad
  • d) To request rectification of personal data that has been processed incompletely or inaccurately
  • e) To request erasure or destruction of personal data within the conditions set out in Article 7 of the Law
  • f) To request that the operations carried out pursuant to subparagraphs (d) and (e) be notified to the third parties to whom the personal data has been transferred
  • g) To object to an adverse outcome arising from the analysis of the processed data exclusively by automated systems
  • ğ) To claim compensation for damage suffered as a result of the unlawful processing of personal data

8.1. Application Procedure

Data subjects have no rights in relation to data that has been anonymised within the Company. Personal data may be shared with the relevant institutions and organisations where required by the business or contractual relationship, or where a legal power is exercised by a judicial or public authority.

Requests within the scope of the listed rights are made by completing the organisation's Application Form in full and submitting it to the Contact Person with your wet signature by registered mail with return receipt, together with copies of your identity document (for the Turkish identity card, a copy of the front side only). For more information about the application process, please see the Personal Data Applications Disclosure Text.

9. Fundamental Rules to Be Observed in Processing Personal Data

When processing the personal data of data subjects, the units and employees of ELEKTRA SOFTWARE will take care to observe the following fundamental rules, upon which the Privacy Policy and other corporate policies are also built:

  • Lawfulness and fairness: The organisation checks and verifies whether the conditions set out in the KVK Law — such as informing the data subject and, where necessary, obtaining the data subject's explicit consent for processing — have been met for the personal data it collects itself or that is shared with it by other parties.
  • Accuracy and being up to date where necessary: The organisation endeavours to ensure, to the extent its control mechanisms permit, that the personal data it processes and holds in its databases is accurate, and keeps that data as up to date as possible.
  • Processing for specified, explicit and legitimate purposes: The organisation processes personal data only for the specified, explicit and legitimate purposes set out in this Privacy Policy.
  • Being relevant, limited and proportionate to the purposes of processing: The organisation takes care not to process personal data for any purpose beyond the limits of the purpose for which it was processed, and uses the data only in a manner limited to that purpose and to the extent required by the service.
  • Storage limitation: The organisation takes care to retain personal data only for the period stipulated in the relevant legislation or required for the purpose of processing, and erases or anonymises the data when those purposes cease to exist.
  • Data minimisation: The organisation, its units and its employees collect data in the categories relevant to the purpose only in the amount required by the processing purpose, save for the scope and periods mandated by law and the relevant legislation.
  • Erasure and destruction: The organisation retains the personal data it processes only for the periods stipulated in the relevant legislation; upon expiry of those periods it erases, destroys or anonymises the data in accordance with the Personal Data Retention, Erasure, Destruction and Transfer Policy.
  • Confidentiality and data security: Throughout all processes of processing, transferring and storing personal data, the organisation observes general confidentiality rules and ensures data security, taking the necessary administrative and technical measures.

10.1. Matters to Be Observed in the Transfer of Personal Data

In order to conduct its production-oriented and commercial activities and to ensure that activities requiring expertise are carried out, ELEKTRA SOFTWARE makes use of service and product suppliers in Türkiye and abroad, and may transfer personal data to such suppliers, business partners or competent institutions and organisations, which — depending on their job descriptions, activities and the nature of the service they provide — are deemed "data processors", "data controllers" or "joint data controllers".

When personal data is shared, the transfer is secured by signing a data transfer agreement, undertaking or similar document with all parties to whom data is transferred.

  • Each unit and employee must anticipate the risks that the recipient of a personal data transfer may create in relation to personal data, and take care to prevent situations that would create risk.
  • Due care is taken to comply with the relevant legislation, such as the KVK Law and the GDPR, when using applications and services originating abroad.
  • During data transfers to counterparties and suppliers, data security must be ensured through appropriate and secure tools and channels, it must be verified whether the natural persons to whom personal data is transferred are authorised by the recipient, and any duplicates/copies created for the purpose of the transfer must be deleted from all media as soon as their function ends.
  • The organisation's units and employees are obliged to observe the sensitivities and practices of the counterparties and suppliers to whom they transfer data regarding personal data, and to report situations that may create risk to their superiors in good time.

10.2. Situations in Which Personal Data Is Transferred and the Parties to Whom It Is Transferred

Personal data is shared for the purposes set out below with the parties likewise set out below:

  • Where necessary for the planning and performance of the commercial activities carried out by the organisation, with private institutions and organisations such as group companies, business partners, affiliates, consultancy firms and other service suppliers in Türkiye and abroad, as well as with public institutions and organisations
  • With natural and legal persons providing services in these fields, and the third parties they work with, for the purpose of ensuring business continuity, providing legal, technical and commercial business security, and planning and executing human resources, occupational health and safety and emergency processes and strategies
  • With the persons with whom the organisation has entered into contracts within the framework of the services it procures, and the third parties they work with
  • With suppliers providing external services in the nature of the services offered by the organisation or of socio-economic benefits to employees, and the third parties they work with
  • With internal departments, our group companies and previous or subsequent employers during recruitment and exit processes
  • Where necessary for the organisation to fulfil its legal obligations, with our business partners, consultancy firms, suppliers, private institutions and organisations, courts, public institutions and organisations and competent authorities
  • With the relevant banks for the payment and collection transactions required within the scope of the conclusion and performance of the contracts entered into by the organisation
  • With insurance agencies and insurance companies so that employees can benefit from insurance and similar entitlements
  • With law and accounting/CPA offices, lawyers and other consultants in order to obtain legal and financial support within the scope of the establishment, exercise and protection of our organisation's rights
  • With service suppliers in Türkiye and abroad providing cloud services, for the infrastructure and services required for corporate electronic communication channels and for ensuring data security
  • With platforms and applications originating abroad from which we procure services in order to use online communication channels and tools such as instant messaging, file sharing, video conferencing and e-mail
  • With the supplier from which we procure services for the provision and authorisation of electronic signatures
  • With supplier organisations providing services in these fields for the purposes of increasing employee motivation and strengthening team spirit, such as sending messages of support on special occasions, organising events and rewarding successful employees
  • With auditors and audit organisations in Türkiye or abroad in order to carry out quality, social and other audits initiated by the organisation or requested by customers
  • With private and public institutions/organisations in order to conduct the legal and technical processes relating to matters of intellectual and industrial property

10.3. Transfer of Personal Data Abroad

For the purpose of providing services through cloud, instant messaging or online communication channels that are widely and unavoidably used today, personal data is shared with the following parties established abroad:

  • With Microsoft, based in the USA, for office work and operations
  • With Facebook (Meta), based in the USA, through the WhatsApp application used as an instant messaging tool between employees and in relationships with customers for business purposes
  • With Google, WeTransfer and Microsoft, based in the USA, for sharing large files for business purposes
  • With Microsoft, based in the USA, through Azure, which provides data centre and cloud server services
  • With Constant Contact, based in the USA, for bulk e-mail management
  • With Ammy, based in the USA, and AnyDesk and TeamViewer, based in Germany, which provide remote access in order to give technical support to customers
  • With Microsoft, based in the USA, through the Skype application for video conferencing services
  • With Google, based in the USA, and Yandex, based in Russia, for our corporate e-mail services
  • With SparkPost (Bird), based in the USA, so that requests submitted through the www.opex.app contact form are delivered to our team by e-mail (delivery is carried out through servers located in the EU region)
  • With Cloudflare, based in the USA (Turnstile service), in order to protect the www.opex.app contact form against automated software (bots)
  • With Apple, Microsoft and Google, based in the USA, which provide the mobile and desktop operating systems used to carry out daily business activities
  • With Facebook, Twitter, Instagram and LinkedIn, based in the USA, which provide social media services from abroad, and with Google, based in the USA, through YouTube

10.3.1. Privacy Policies of Service Providers

You can access the privacy policy of each service provider through the links below:

  • Microsoft: https://privacy.microsoft.com/en-us/privacystatement
  • WhatsApp: https://www.whatsapp.com/legal/client
  • Google: https://policies.google.com/privacy?hl=en-US
  • WeTransfer: https://wetransfer.com/legal/privacy
  • Constant Contact: https://www.endurance.com/privacy/privacy
  • Ammy: https://www.ammyy.com/en/priv_policy.html
  • AnyDesk: https://anydesk.com/en/privacy
  • TeamViewer: https://www.teamviewer.com/en/privacy-policy/
  • Skype: https://support.skype.com/en/skype/all/privacy-security/
  • Yandex: https://yandex.com.tr/support/legal/confidential/01032016/index.html?lang=en
  • SparkPost (Bird): https://bird.com/legal/privacy-statement
  • Apple: https://www.apple.com/legal/privacy/en-ww/
  • Facebook: https://www.facebook.com/policy.php
  • Twitter: https://twitter.com/en/privacy
  • Instagram: https://help.instagram.com/519522125107875
  • LinkedIn: https://www.linkedin.com/legal/privacy-policy
  • Cloudflare: https://www.cloudflare.com/privacypolicy/

11. Audits, Applications and Data Breach Notifications

The organisation may arrange for the necessary internal and external audits regarding the protection of personal data.

Applications made by data subjects are answered within 30 days at the latest by the Committee, after obtaining the opinion of the relevant unit.

When the organisation is notified of any breach relating to personal data, it notifies the Personal Data Protection Board without delay and within 72 hours at the latest from the date on which it became aware of the situation. It informs the relevant parties and persons in the same manner.

12. Updates

This policy document is updated when the organisation's personal data processing conditions, means, purposes and scope change, and when the parties with whom personal data is shared change. Updates made to each article are kept in a separate table.

Language of This Text

This is an English translation provided for convenience. In case of any discrepancy between the Turkish and English versions, the Turkish version prevails.