Data Controller & Scope
DAYLOO Software Engineering is the Data Controller for personal data processed through this website and technical communication channels.
This Privacy Policy applies to DAYLOO’s official website (dayloo.tech), subdomains, and technical communication channels. As a premier software engineering firm headquartered in Istanbul, Türkiye, we operate as a Data Controller in accordance with the European Union General Data Protection Regulation (GDPR) and the Turkish Law on the Protection of Personal Data No. 6698 (KVKK).
Please note a critical distinction: for enterprise production systems engineered for our enterprise clients, DAYLOO acts as a Data Processor under dedicated, bilateral Enterprise Data Processing Agreements (DPAs) governed by isolated infrastructure and strict NDAs.
Controller Information
- Legal Entity: DAYLOO Software Engineering
- Headquarters: Istanbul, Türkiye
- Privacy Inquiries: privacy@dayloo.tech
- General Inquiries: hello@dayloo.tech
Core Privacy Principles
Privacy at DAYLOO is treated with the same rigor as mission-critical systems engineering.
We engineer privacy into our system architectures by default rather than applying after-the-fact compliance layers. Every engineering decision is guided by four principles:
Our Four Pillars
- Privacy by Design: Database schemas are designed to prohibit unnecessary telemetry or personal data retention.
- Principle of Least Privilege: Zero unauthorized personnel or developers have access to contact forms or user records.
- No Stealth Tracking: We never embed third-party advertising cookies or covert behavioral tracking scripts.
- Absolute Transparency: We explicitly state where data resides, how it is secured, and who holds audit rights.
Categories of Data We Collect
We exclusively collect information you voluntarily provide in project inquiries and job applications, along with minimal infrastructure security telemetry.
We do not purchase third-party mailing lists, nor do we scrape data from secondary sources. Data collected is strictly limited to the following categories:
1. Project Inquiries & Commercial Communications
When submitting our contact form or initiating an architectural consultation:
- Full name and business role.
- Corporate email address and phone number (if provided).
- Organization name and sector.
- Project scope, estimated budget range, timelines, and technical requirements.
2. Recruitment & Engineering Candidate Submissions
When applying for engineering positions via our Careers portal (/careers):
- Full legal name and direct contact information.
- Curriculum Vitae (CV), portfolio links (GitHub, LinkedIn, personal tech blog).
- Engineering competencies, stack preferences, and work history.
- Compensation expectations and availability timelines.
3. Technical & Infrastructure Telemetry
When browsing dayloo.tech, our edge infrastructure logs essential security data:
- Truncated/anonymized IP addresses for DDoS mitigation and regional CDN routing.
- User-Agent strings (browser family, OS version, viewport dimensions).
- Request timestamps in standard Latin format (e.g., 2026-10-10 01:00:00).
- Diagnostic error traces and Web Application Firewall (WAF) challenge logs.
Legal Bases for Processing (GDPR & KVKK)
Every processing activity is grounded in explicit legal bases under GDPR and KVKK legislation.
In compliance with GDPR Article 6 and KVKK Articles 5 & 6, we process personal data under the following legitimate grounds:
Applicable Legal Grounds
- Contractual Necessity (GDPR Art. 6(1)(b) / KVKK Art. 5(2)(c)): Processing communications to prepare project scopes, engineering proposals, and enter into service contracts.
- Legitimate Interests (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)): Protecting platform uptime, mitigating cyberattacks, and maintaining infrastructure integrity.
- Legal Compliance (GDPR Art. 6(1)(c) / KVKK Art. 5(2)(ç)): Meeting statutory accounting, taxation, and statutory logging requirements under Turkish and international laws.
- Explicit Consent (GDPR Art. 6(1)(a) / KVKK Art. 5(1)): When explicitly provided for job candidate evaluations or optional communications.
Purposes of Data Processing
Your data is processed strictly for delivering engineering consultations, responding to inquiries, and candidate hiring.
We strictly limit data processing to legitimate business and engineering operations. Our defined purposes include:
Operational Purposes
- Responding to client architectural consultations within 1 business day.
- Conducting technical candidate evaluations, code reviews, and interview scheduling.
- Scoping and authoring formal engineering contracts and milestone specifications.
- Detecting, preventing, and investigating malicious cyber attacks and infrastructure abuses.
- Fulfilling statutory tax and commercial audit obligations.
Technical Security & Architectural Hardening
We implement enterprise-tier safeguards: TLS 1.3 in transit, AES-256 at rest, and zero unauthorized staff access.
Given our background in high-availability, regulated systems engineering, we hold our own public surface to the same exacting standards:
Security Measures in Effect
- In-Transit Cryptography: All HTTP traffic enforces modern TLS 1.3 with strict HSTS preloading.
- At-Rest Cryptography: Database volumes, stored attachments, and backups are encrypted with AES-256.
- Identity & Access Management: Multi-Factor Authentication (MFA) and strict Role-Based Access Control (RBAC).
- VPC Network Isolation: Cloud databases and backend compute run within private Virtual Private Clouds inaccessible from the public internet.
- Continuous Audits: Automated static analysis, software bill of materials (SBOM) scanning, and regular code reviews.
Data Retention Schedules
Data is retained only as long as required for its designated engineering or legal purpose, after which it is cryptographically sanitized.
We adhere to rigorous retention limits calibrated to each data classification:
| Data Category | Retention Schedule | End-of-Life Action |
|---|---|---|
| Project Inquiries & Scopes | 24 months from last active correspondence | Permanent cryptographic purge from database |
| Candidate CVs & Applications | 12 months for active role matching | Secure deletion unless earlier erase requested |
| Technical Telemetry & WAF Logs | 30 to 90 days maximum | Automated FIFO log rotation and erasure |
| Statutory Financial Records | 10 years under Turkish Commercial Code | Segregated legal archive, followed by secure destruction |
Your Statutory Data Rights
Under GDPR and KVKK, you possess unalienable rights to control, inspect, correct, and delete your personal records.
You hold comprehensive rights over your personal data at all times:
Statutory Rights Catalog
- Right of Access: Request confirmation of processing and receive an export of your personal data.
- Right to Rectification: Correct incomplete, inaccurate, or outdated personal information.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of records when lawful retention grounds expire.
- Right to Restriction of Processing: Temporarily freeze processing during accuracy disputes.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing conducted under legitimate interests.
- Right to Withdraw Consent: Revoke previously granted consent without penalty.
- Right to Lodge a Complaint: File a formal complaint with the Turkish KVKK Board or your EEA Supervisory Authority.
Infrastructure & Subprocessors
We exclusively partner with enterprise cloud providers certified to SOC 2 Type II and ISO 27001 standards.
To ensure 99.999% platform availability and low latency, we rely on vetted enterprise infrastructure partners bound by rigorous Data Processing Agreements (DPAs):
Vetted Infrastructure Classes
- Cloud Hosting & Edge CDN: Enterprise cloud infrastructure located in EU and compliant data centers.
- Managed Database Infrastructure: Fully encrypted PostgreSQL instances housed in isolated VPC networks.
- Transactional Email Routing: Hardened email delivery services bound by strict DPAs that do not store message payloads.
Cross-Border Data Transfers
International transfers adhere to Standard Contractual Clauses (SCCs) and statutory KVKK transfer mechanisms.
Given DAYLOO’s global client base and distributed cloud edge nodes, data may be processed across international borders. Whenever cross-border transfers occur, we implement robust safeguards:
We enforce European Commission-approved Standard Contractual Clauses (SCCs) and comply with KVKK Article 9 transfer mechanisms, backed by robust end-to-end encryption.
Exercising Your Rights & Contacting DPO
Our legal and engineering team acknowledges all privacy requests promptly and resolves them within 30 calendar days.
To exercise any statutory rights, request data exports, or petition for permanent deletion, contact us directly:
Request Procedure
- Direct inquiries to: privacy@dayloo.tech
- Specify your request in the subject line (e.g., "Data Erasure Request", "Access Request").
- We acknowledge receipt within 24 to 48 hours.
- Requests are fulfilled completely free of charge within a statutory maximum of 30 calendar days.
Questions about your data or wish to request erasure?
Acknowledged within 24-48 hours; resolved within 30 calendar days
Our engineering and legal team handles every privacy inquiry with direct accountability and zero bureaucracy.
