Privacy policy
Last updated
This site collects one thing: what you type into the contact form, and only when you submit it. It sets no cookies, runs no advertising or profiling, and keeps no database. This policy says exactly what happens to what you send, and what you can require of us.
1. Scope
1.1 This policy covers the website at puenteglobal.com and the contact form on it. It does not cover work carried out for clients under a separate contract, where a separate data processing agreement applies. The terms of use and the cookie policy sit alongside this one.
1.2 Puente Global is established in Türkiye and works with clients in the European Union, the United Kingdom and the United States. Turkish Law No. 6698 on the Protection of Personal Data (KVKK), the EU General Data Protection Regulation (Regulation 2016/679) and the UK GDPR can each apply, depending on where you are. Where they differ, this policy states both positions rather than the more convenient one.
2. Who is responsible
2.1 The data controller, and the veri sorumlusu for KVKK purposes, is Puente Global.
2.2 For any question about this policy or to exercise a right under section 8, write to info@puenteglobal.com. That address reaches a person, not a ticketing queue.
2.3 No data protection officer has been appointed. On the processing described here an appointment is not required under GDPR Article 37, because the processing is neither large-scale nor systematic monitoring.
3. What is collected
3.1 The contact form collects five fields, and nothing else on this site collects anything:
- Name: required, as you type it.
- Email address: required, and used as the reply-to address.
- Inquiry type: required, one of five fixed options.
- Interested in: optional, one of four fixed options.
- Message: optional, free text, up to 5,000 characters.
3.2 Two further fields are submitted and are not personal data about you: a hidden field that must stay empty, which catches automated submissions, and a timestamp of when the page loaded, which rejects submissions made faster than a person can type. Neither is stored and neither is included in the email.
3.3 Your IP address is seen by the server when you submit the form. It is held in memory only, for the rate limit described in section 6.3. It is never written to disk, never included in the email, and never sent anywhere.
3.4 No account exists, so no credentials are collected. No payment is taken on this site, so no payment data is collected. No special categories of personal data under KVKK Article 6 or GDPR Article 9 are requested, and the form should not be used to send any.
4. Why, and on what legal basis
4.1 To answer your enquiry. Legal basis under GDPR and UK GDPR: Article 6(1)(b), steps taken at your request before entering into a contract, or Article 6(1)(f), our legitimate interest in replying to someone who has asked us a question. Under KVKK: Article 5(2)(c), where processing is necessary in connection with a contract, and Article 5(2)(f), legitimate interests, provided your fundamental rights are not harmed. You supply the data yourself and can decline to.
4.2 To stop the form being abused. The honeypot, the timing check and the IP rate limit exist to keep automated submissions out. Legal basis: GDPR Article 6(1)(f) and KVKK Article 5(2)(f), legitimate interests in the security and availability of our own service.
4.3 To count page views. Aggregate, anonymous, and not tied to you. See section 5.2 and the cookie policy. Legal basis: GDPR Article 6(1)(f) and KVKK Article 5(2)(f). Because no identifier is stored on your device, no consent is required under the ePrivacy Directive or its Turkish equivalent.
4.4 There is no marketing list, no newsletter and no profiling. Your details are not used to contact you about anything other than the enquiry you sent.
5. Who else sees it
5.1 Resend (Plus Five Five, Inc., United States) delivers the email. It receives your name, your email address, your inquiry type, your interest and your message, because those are the contents of the email. It acts as a processor.
5.2 Vercel (Vercel Inc., United States) hosts the site and runs the function that sends the email. It processes the form submission in transit and handles the page-view counting described in the cookie policy. It acts as a processor.
5.3 That is the complete list. There are no advertising networks, no analytics brokers, no tag managers, no session recorders, no chat widgets and no embedded third-party content. Measured on the built site: a browser loading any page of puenteglobal.com contacts no origin other than the site itself.
5.4 We do not sell personal data and we do not share it for anyone else's marketing. We would disclose it if a court or a competent authority lawfully required it, and we would tell you unless prohibited from doing so.
6. How long it is kept
6.1 In our systems: not at all. There is no database and no file store. Your submission becomes an email and nothing else.
6.2 In our inbox: the email sits in the info@puenteglobal.com mailbox for as long as the correspondence is live, and is deleted when it is no longer needed. If it becomes part of a client relationship it is retained under that engagement's own terms.
6.3 The rate limit: your IP address and the times you submitted are held in the server's memory for at most one hour, and are discarded when that hour passes or when the server instance is recycled, whichever comes first. Nothing about it survives a restart.
6.4 Page views: aggregate counts, with no identifier tied to you. Vercel discards the per-request hash it uses to group a visit after 24 hours.
7. Transfers out of Türkiye, the EEA and the UK
7.1 Your form submission is processed in the United States. The
request reaches Vercel's Frankfurt edge, but the function that handles it executes in
Vercel's iad1 region in Washington, DC, and Resend states in its data
processing agreement that its primary processing operations take place in the United
States. This is stated because it is true, not because it is ideal.
7.2 For EU and UK data subjects. Both processors provide Article 46 safeguards. Resend's data processing agreement provides that transfers out of the EEA are made under the EU Standard Contractual Clauses approved by the European Commission in Decision 2021/914 of 4 June 2021, that transfers out of the UK are made under the UK SCCs as amended by the UK Addendum, and that Resend complies with the EU–U.S. Data Privacy Framework and its UK Extension. Vercel's data processing agreement incorporates the same Commission Decision 2021/914 clauses and provides that the UK International Data Transfer Addendum is deemed entered into for UK transfers.
7.3 For KVKK, the position is not yet settled and we are not going to pretend otherwise. Article 9 of Law No. 6698, as amended by Law No. 7499 and in force since 1 June 2024, permits a transfer abroad where there is an adequacy decision, failing that where an appropriate safeguard such as a standard contract is in place, and failing that in limited exceptional cases. The Board has issued no adequacy decision covering the United States. The applicable route is therefore a standard contract under Article 9(2), which must be adopted in the Board's own form and notified to the Authority within five business days of signature. Whether that notification has been made for Resend and for Vercel is being confirmed. Until it is, treat this paragraph as a statement of the route that applies rather than a representation that every step of it is complete. If you are in Türkiye and this matters to your decision to contact us, email us before you use the form and we will tell you where it stands.
8. Your rights
8.1 Under GDPR and UK GDPR you have the right to: confirmation and access to your data (Article 15); rectification of inaccurate data (Article 16); erasure (Article 17); restriction of processing (Article 18); notification to recipients of a rectification, erasure or restriction (Article 19); portability of data you provided, in a machine-readable form (Article 20); objection to processing based on legitimate interests, including at any time (Article 21); and not to be subject to a decision based solely on automated processing (Article 22).
8.2 Under KVKK Article 11 you have the right to: learn whether your data is processed; request information if it has been; learn the purpose and whether it is used consistently with that purpose; know the third parties at home or abroad to whom it is transferred; request correction if it is incomplete or inaccurate, and that the correction be notified to those third parties; request erasure or destruction under Article 7, and that this too be notified; object to a result produced solely by automated analysis that is to your detriment; and claim compensation for damage caused by unlawful processing.
8.3 How to exercise them. Email info@puenteglobal.com. Say which right you are exercising and give us enough to find the correspondence, which is usually the email address you used. We may ask you to confirm your identity, and we will ask for no more than is needed to do that.
8.4 How long we take. Under GDPR and UK GDPR, within one month of the request, extendable by two further months for complex requests, in which case we will tell you within the first month. Under KVKK Article 13, at the latest within 30 days. Where both could apply we work to the shorter one. There is no charge unless a request is manifestly unfounded or excessive.
8.5 If you are not satisfied. In Türkiye you may complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, KVKK), after first applying to us as Article 13 requires. In the EU you may complain to the supervisory authority of your Member State. In the UK you may complain to the Information Commissioner's Office. Complaining to an authority does not stop you pursuing a remedy in court.
9. Automated decisions and children
9.1 There is no automated decision-making and no profiling within the meaning of GDPR Article 22 or KVKK Article 11(g). The honeypot and timing checks reject automated submissions; they make no decision about a person.
9.2 This site is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has sent us something, email us and we will delete it.
10. Security
10.1 The site is served over HTTPS only. The form submission is encrypted in transit. The credential used to send email is held as a server-side environment variable, is never sent to the browser, and does not appear anywhere in the site's source or built output.
10.2 No system is perfectly secure and we do not claim otherwise. If you find a vulnerability, email info@puenteglobal.com and we will respond.
11. Changes
11.1 If this policy changes, the "last updated" date at the top of the page changes with it. That date is generated from the change itself, so it cannot be stale.
11.2 For a change that materially affects how we handle data already sent to us, we will say so on this page and, where we hold your address because of a live correspondence, by email.