Home
00Legal & Privacy

Privacy Policy & Data Protection

At DAYLOO, data sovereignty and privacy are foundational architectural decisions. We do not sell your personal data, we deploy zero advertising trackers, and we protect every bit with bank-grade encryption.

October 2026Version 2.4.0Active & EnforcedGDPR & KVKK Aligned

Zero Data Brokering

We never sell, rent, or trade your personal data to ad networks, brokers, or third parties.

Architectural Encryption

Complete transit encryption via TLS 1.3 and at-rest database encryption via AES-256.

Strict Minimization

We only collect the absolute minimum required to provide engineering consultations and services.

Full Data Sovereignty

You retain the complete statutory right to access, rectify, export, or permanently erase your data.

01

Data Controller & Scope

Key Takeaway

DAYLOO Software Engineering is the Data Controller for personal data processed through this website and technical communication channels.

This Privacy Policy applies to DAYLOO’s official website (dayloo.tech), subdomains, and technical communication channels. As a premier software engineering firm headquartered in Istanbul, Türkiye, we operate as a Data Controller in accordance with the European Union General Data Protection Regulation (GDPR) and the Turkish Law on the Protection of Personal Data No. 6698 (KVKK).

Please note a critical distinction: for enterprise production systems engineered for our enterprise clients, DAYLOO acts as a Data Processor under dedicated, bilateral Enterprise Data Processing Agreements (DPAs) governed by isolated infrastructure and strict NDAs.

Controller Information

  • Legal Entity: DAYLOO Software Engineering
  • Headquarters: Istanbul, Türkiye
  • Privacy Inquiries: privacy@dayloo.tech
  • General Inquiries: hello@dayloo.tech
02

Core Privacy Principles

Key Takeaway

Privacy at DAYLOO is treated with the same rigor as mission-critical systems engineering.

We engineer privacy into our system architectures by default rather than applying after-the-fact compliance layers. Every engineering decision is guided by four principles:

Our Four Pillars

  • Privacy by Design: Database schemas are designed to prohibit unnecessary telemetry or personal data retention.
  • Principle of Least Privilege: Zero unauthorized personnel or developers have access to contact forms or user records.
  • No Stealth Tracking: We never embed third-party advertising cookies or covert behavioral tracking scripts.
  • Absolute Transparency: We explicitly state where data resides, how it is secured, and who holds audit rights.
03

Categories of Data We Collect

Key Takeaway

We exclusively collect information you voluntarily provide in project inquiries and job applications, along with minimal infrastructure security telemetry.

We do not purchase third-party mailing lists, nor do we scrape data from secondary sources. Data collected is strictly limited to the following categories:

1. Project Inquiries & Commercial Communications

When submitting our contact form or initiating an architectural consultation:

  • Full name and business role.
  • Corporate email address and phone number (if provided).
  • Organization name and sector.
  • Project scope, estimated budget range, timelines, and technical requirements.

2. Recruitment & Engineering Candidate Submissions

When applying for engineering positions via our Careers portal (/careers):

  • Full legal name and direct contact information.
  • Curriculum Vitae (CV), portfolio links (GitHub, LinkedIn, personal tech blog).
  • Engineering competencies, stack preferences, and work history.
  • Compensation expectations and availability timelines.

3. Technical & Infrastructure Telemetry

When browsing dayloo.tech, our edge infrastructure logs essential security data:

  • Truncated/anonymized IP addresses for DDoS mitigation and regional CDN routing.
  • User-Agent strings (browser family, OS version, viewport dimensions).
  • Request timestamps in standard Latin format (e.g., 2026-10-10 01:00:00).
  • Diagnostic error traces and Web Application Firewall (WAF) challenge logs.
05

Purposes of Data Processing

Key Takeaway

Your data is processed strictly for delivering engineering consultations, responding to inquiries, and candidate hiring.

We strictly limit data processing to legitimate business and engineering operations. Our defined purposes include:

Operational Purposes

  • Responding to client architectural consultations within 1 business day.
  • Conducting technical candidate evaluations, code reviews, and interview scheduling.
  • Scoping and authoring formal engineering contracts and milestone specifications.
  • Detecting, preventing, and investigating malicious cyber attacks and infrastructure abuses.
  • Fulfilling statutory tax and commercial audit obligations.
06

Technical Security & Architectural Hardening

Key Takeaway

We implement enterprise-tier safeguards: TLS 1.3 in transit, AES-256 at rest, and zero unauthorized staff access.

Given our background in high-availability, regulated systems engineering, we hold our own public surface to the same exacting standards:

Security Measures in Effect

  • In-Transit Cryptography: All HTTP traffic enforces modern TLS 1.3 with strict HSTS preloading.
  • At-Rest Cryptography: Database volumes, stored attachments, and backups are encrypted with AES-256.
  • Identity & Access Management: Multi-Factor Authentication (MFA) and strict Role-Based Access Control (RBAC).
  • VPC Network Isolation: Cloud databases and backend compute run within private Virtual Private Clouds inaccessible from the public internet.
  • Continuous Audits: Automated static analysis, software bill of materials (SBOM) scanning, and regular code reviews.
07

Cookies & Storage Policy

Key Takeaway

We maintain a zero-advertising cookie policy. We only store strictly essential operational cookies.

Unlike consumer web platforms, DAYLOO does not deploy third-party advertising tracking scripts or behavioral cookies. Our cookie footprint is strictly minimal:

Essential Storage Items

  • Locale Preference Token: Remembers your selected language (ar, en, tr) across navigation cycles.
  • CSRF Security Token: Protects contact and career forms from cross-site request forgery attacks.
  • Zero Marketing Pixels: No Facebook/Meta Pixel, no Google Ads remarketing, no LinkedIn Insight trackers.
08

Data Retention Schedules

Key Takeaway

Data is retained only as long as required for its designated engineering or legal purpose, after which it is cryptographically sanitized.

We adhere to rigorous retention limits calibrated to each data classification:

Data CategoryRetention ScheduleEnd-of-Life Action
Project Inquiries & Scopes24 months from last active correspondencePermanent cryptographic purge from database
Candidate CVs & Applications12 months for active role matchingSecure deletion unless earlier erase requested
Technical Telemetry & WAF Logs30 to 90 days maximumAutomated FIFO log rotation and erasure
Statutory Financial Records10 years under Turkish Commercial CodeSegregated legal archive, followed by secure destruction
09

Your Statutory Data Rights

Key Takeaway

Under GDPR and KVKK, you possess unalienable rights to control, inspect, correct, and delete your personal records.

You hold comprehensive rights over your personal data at all times:

Statutory Rights Catalog

  • Right of Access: Request confirmation of processing and receive an export of your personal data.
  • Right to Rectification: Correct incomplete, inaccurate, or outdated personal information.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of records when lawful retention grounds expire.
  • Right to Restriction of Processing: Temporarily freeze processing during accuracy disputes.
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object: Object to processing conducted under legitimate interests.
  • Right to Withdraw Consent: Revoke previously granted consent without penalty.
  • Right to Lodge a Complaint: File a formal complaint with the Turkish KVKK Board or your EEA Supervisory Authority.
10

Infrastructure & Subprocessors

Key Takeaway

We exclusively partner with enterprise cloud providers certified to SOC 2 Type II and ISO 27001 standards.

To ensure 99.999% platform availability and low latency, we rely on vetted enterprise infrastructure partners bound by rigorous Data Processing Agreements (DPAs):

Vetted Infrastructure Classes

  • Cloud Hosting & Edge CDN: Enterprise cloud infrastructure located in EU and compliant data centers.
  • Managed Database Infrastructure: Fully encrypted PostgreSQL instances housed in isolated VPC networks.
  • Transactional Email Routing: Hardened email delivery services bound by strict DPAs that do not store message payloads.
11

Cross-Border Data Transfers

Key Takeaway

International transfers adhere to Standard Contractual Clauses (SCCs) and statutory KVKK transfer mechanisms.

Given DAYLOO’s global client base and distributed cloud edge nodes, data may be processed across international borders. Whenever cross-border transfers occur, we implement robust safeguards:

We enforce European Commission-approved Standard Contractual Clauses (SCCs) and comply with KVKK Article 9 transfer mechanisms, backed by robust end-to-end encryption.

12

Exercising Your Rights & Contacting DPO

Key Takeaway

Our legal and engineering team acknowledges all privacy requests promptly and resolves them within 30 calendar days.

To exercise any statutory rights, request data exports, or petition for permanent deletion, contact us directly:

Request Procedure

  • Direct inquiries to: privacy@dayloo.tech
  • Specify your request in the subject line (e.g., "Data Erasure Request", "Access Request").
  • We acknowledge receipt within 24 to 48 hours.
  • Requests are fulfilled completely free of charge within a statutory maximum of 30 calendar days.

Questions about your data or wish to request erasure?

Acknowledged within 24-48 hours; resolved within 30 calendar days

Our engineering and legal team handles every privacy inquiry with direct accountability and zero bureaucracy.