Skip to content
Free Introductory Call
LEGAL NOTICE

Privacy Policy and KVKK Disclosure Notice

This page explains how personal data is processed in connection with the corporate structuring and process coordination activities carried out by MEY Investment. It satisfies the disclosure obligation under Article 10 of the Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu) No. 6698 and also applies as our privacy policy and cookie policy.

1. Identity of the Data Controller

This notice has been prepared pursuant to Article 10 of the Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu) No. 6698 and the provisions of the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Disclosure Obligation. Its scope covers all processing activities carried out, in the capacity of data controller, by the legal entity whose particulars are set out below. Website visitors, individuals who submit forms, those who request a consultation, and natural persons who receive services are the addressees of this notice.

The data controller is the party that determines the purposes and means of processing the data collected through the website and that is responsible for establishing and administering the data filing system. The identification fields below will be completed before publication, verified against the trade registry and official records. A disclosure notice published with incomplete particulars does not meet the standard of transparency required by the Law.

For the purpose of fulfilling obligations under the Law, whether an obligation to register with VERBİS (the Data Controllers' Registry Information System) arises is assessed separately, on the basis of employee headcount, annual financial balance sheet total, and principal line of business. Where the registration obligation applies, the registry details will be published in this section.

  • Legal name: [To be completed before publication: full registered trade name]
  • Address: [To be completed before publication: head office address]
  • MERSİS / Tax ID: [To be completed before publication]
  • Email: [To be completed before publication: KVKK request email address]
  • Registered electronic mail (KEP) address: [To be completed before publication]
  • Telephone: [To be completed before publication]
  • VERBİS registration details: [To be completed before publication: registry number if registered, otherwise exemption note]
  • Affiliated legal entity on the UAE side: [To be completed before publication: legal name, license number, free zone registration or, for mainland, Dubai Department of Economy and Tourism (DET) registration]

2. Categories of Personal Data Processed

The data processed varies according to the point of contact and the service requested. The data set of a visitor who has only submitted a contact form is not the same as that of a client for whom a company formation file has been opened. In line with the data minimization principle, only the data required at a given stage is requested at that stage. No passport, proof of address, or financial document is requested at the preliminary consultation stage.

Once a file has been opened, the documents required by the licensing, residency, and banking processes in the UAE are collected. These documents are limited to the minimum scope requested by the relevant authorities and by the compliance departments of financial institutions. In bank account opening processes, information such as source of income and source of funds declarations is submitted directly to the bank in accordance with the bank's own compliance policy.

Inputs entered into the calculator tools on the website — amounts, revenue, ownership percentages, and time periods — are processed in order to generate a simulation output. Although such inputs do not on their own make an individual identifiable, they acquire the character of personal data when submitted together with contact details and are treated within the scope of this notice. Calculator outputs are indicative and are not a binding calculation result.

CategorySample dataStage of collection
IdentityGiven name, surname, date of birth, nationality, passport detailsFile opening
ContactEmail, telephone, country/city, preferred consultation channelForm and preliminary consultation
Client transactionSubject of the request, consultation notes, file progress recordsService process
FinancialInvoicing details, payment reference, bank file attachmentsContract and payment
Transaction securityIP address, browser and device information, session and log recordsWebsite visit
MarketingNewsletter subscription, open/click data, consent recordAfter explicit consent
Form and calculator inputsCapital, revenue, ownership structure, target zone, budget rangeTool usage
Data categories, sample data types, and the stage at which they are collected

3. Purposes of Processing Personal Data

Personal data is processed for specified, explicit, and legitimate purposes, in accordance with the general principles set out in Article 4 of the Law. The primary purpose is to respond to the visitor's request and, once that request becomes an engagement, to coordinate the processes relating to company formation, residency permits, bank account applications, and real estate transactions. Data is not used for any purpose beyond this and is not subjected to any processing unconnected with the purpose.

Process coordination covers the complete transmission of the relevant file to licensed professionals, free zone authorities, GDRFA in Dubai, ICP in the other emirates, banks, and, on the real estate side, authorized brokers. Data is therefore also processed for the purpose of file preparation and completion of official applications. The data controller gives no undertaking regarding application outcomes; approval and the time to completion are at the discretion of the competent authority or of the bank's compliance department.

Processing is also carried out for the purposes of fulfilling contractual and financial obligations, invoicing, maintaining orderly records and archives, measuring service quality, ensuring the security and continuity of the website, detecting misuse and fraud attempts, marketing communications where explicit consent exists, and responding to legal requests and audits.

  • Assessing requests and applications and scheduling the preliminary consultation
  • Preparing the file and compiling official application documents
  • Coordinating with licensed professionals and competent authorities
  • Concluding contracts, invoicing, and monitoring collections
  • Website security, log retention, and prevention of misuse
  • Customer due diligence within the scope of AML/KYC obligations
  • Sending newsletters and announcements on the basis of explicit consent

4. Legal Grounds for Processing

Every processing activity is based on at least one of the legal grounds listed in Article 5 of the Law. Explicit consent is relied on only where no other legal ground exists; data that is necessary for the performance of the contract is not made conditional on explicit consent. This distinction matters, because where processing is not based on consent, withdrawing consent does not on its own bring the processing to an end.

For requests received through the contact form, Article 5(2)(c) applies, given the nature of the preparatory stage preceding the conclusion of a contract. Log records relating to website security and the detection of misuse rest on the legitimate interests of the data controller and are assessed under Article 5(2)(f); in doing so, care is taken not to harm the fundamental rights and freedoms of the data subject.

For invoices, accounting records, and documents subject to retention obligations, Articles 5(2)(a) and 5(2)(ç) apply. For marketing communications and non-essential cookies, the sole basis is explicit consent, and that consent may be withdrawn at any time.

Processing activityLegal groundKVKK article
Responding to a form requestNecessary for the conclusion/performance of a contractart. 5(2)(c)
Carrying out the service fileNecessary for the performance of a contractart. 5(2)(c)
Invoicing and accounting recordsCompliance with a legal obligationart. 5(2)(ç)
Log retention, security, and misuse detectionLegitimate interestsart. 5(2)(f)
Measuring service quality, analytics cookiesExplicit consentart. 5(1)
Newsletters and commercial electronic messagesExplicit consentart. 5(1)
Exercising the right of defense in a disputeEstablishment and protection of a rightart. 5(2)(e)
Processing activity and the legal ground relied on

5. Transfers and Cross-Border Transfers

Personal data may be transferred provided that the conditions in Articles 8 and 9 of the Law are met. Domestic transfers are made to licensed professionals providing accounting and tax advisory services, to the relevant law firm where legal services are engaged, to IT infrastructure providers, to payment institutions, and to competent public authorities and agencies, upon request and limited to the legal basis of that request.

Given the nature of the activity, cross-border transfer is unavoidable. In order to carry out company formation, residency permit, and bank account processes, data is transferred to the affiliated legal entity located in the United Arab Emirates, to free zone authorities, to the relevant registration and immigration authorities (GDRFA in Dubai, ICP in the other emirates), to banks, and, on the real estate side, to authorized brokers. In addition, email, form, CRM, and hosting services may run on servers located abroad.

The cross-border transfer regime is applied within the framework of the amendment to Article 9 of Law No. 6698, introduced by Law No. 7499, which was adopted on March 2, 2024, published in the Official Gazette of March 12, 2024, and entered into force on June 1, 2024. Accordingly, a transfer is carried out, in order of priority, on the basis of an adequacy decision announced by the Board; where there is no adequacy decision, by providing one of the appropriate safeguards; and where neither is possible, by relying, on an incidental basis only, on one of the derogations listed in that article.

As of the date this notice was last updated, no adequacy decision has been announced in respect of the United Arab Emirates; accordingly, the standard contract is used as the principal appropriate safeguard. The standard contract is notified to the Personal Data Protection Authority within five business days of signature. Binding corporate rules are subject to Board approval and the written undertaking route is subject to Board authorization; where these routes are used, the relevant procedure is carried out separately. The recipient groups to which data is transferred and the safeguard relied on are disclosed to the data subject upon request.

  • Recipient group: the affiliated legal entity in the UAE and the corporate service providers it authorizes
  • Recipient group: free zone authorities, departments of economy, and immigration authorities (GDRFA in Dubai, ICP in the other emirates)
  • Recipient group: compliance departments of banks and financial institutions
  • Recipient group: brokers registered with the Dubai Land Department and RERA, and authorized parties involved in title deed transactions
  • Recipient group: email, hosting, CRM, and analytics service providers based abroad

6. Method of Collecting Personal Data

Data is collected through the contact and appointment forms on the website, calculator tools, email correspondence, telephone and instant messaging channels, online or in-person meetings, contract and invoicing processes, and cookies and similar tracking technologies, by wholly or partly automated means or by non-automated means forming part of a data filing system.

In certain cases, data may be obtained not directly from the data subject but from third parties. For example, trade registry records may be checked in order to verify ownership structure, and publicly available sanctions lists and politically exposed person lists may be screened in the context of compliance obligations. These sources are used only to the extent required by the customer due diligence procedure.

Where a natural person submits data belonging to persons other than themselves (for example, information about a partner, family member, or employee), it is that person's responsibility to inform those individuals about this notice and to ensure the necessary legal basis. The data controller acts on the assumption that data relating to third parties has been obtained lawfully.

7. Retention Periods

Personal data is retained for as long as necessary for the purposes for which it is processed, taking into account the minimum retention periods prescribed by the relevant legislation. Once those periods expire, data is erased, destroyed, or anonymized in accordance with Article 7 of the Law and the Regulation on the Erasure, Destruction, or Anonymization of Personal Data.

A periodic destruction process is applied under the retention and destruction policy. Periodic destruction is carried out at intervals not exceeding six months, without exceeding the maximum periods prescribed by legislation. Records of destroyed data are kept separately for auditability. The periods in the table below are indicative; they may be extended or shortened depending on the legal position of the specific file and on changes in legislation.

Where a dispute, official investigation, or audit is ongoing, the relevant data is retained until the process has been definitively concluded. In such cases, an erasure request may be refused, but only on the ground of the establishment and protection of a right, and the reason for refusal is communicated to the data subject in writing.

Data typeRetention periodBasis
Form and preliminary consultation records (not converted into an engagement)1 year from conclusion of the requestLegitimate interests, internal policy
Client file and contract records10 years from the end of the legal relationshipCode of Obligations (Türk Borçlar Kanunu) art. 146, general statute of limitations
Invoices and accounting documents5 years for tax procedure purposes; 10 years for commercial books and recordsTax Procedure Law (Vergi Usul Kanunu) art. 253; Commercial Code (Türk Ticaret Kanunu) art. 82
Customer due diligence (KYC) documents8 years from the end of the relationshipAnti-Money Laundering Law (Suç Gelirlerinin Aklanmasının Önlenmesi Hakkında Kanun) No. 5549 art. 8 and related regulation
Website log recordsMaximum 2 yearsLaw No. 5651 (İnternet Ortamında Yapılan Yayınların Düzenlenmesi Hakkında Kanun) and related regulation
Marketing consent and consent records3 years from the expiry of the validity of the consentRegulation on Commercial Communication and Commercial Electronic Messages art. 13
Cookie dataSession duration up to 24 months, depending on cookie typeExplicit consent, cookie table
Indicative retention periods by data type

8. Rights of the Data Subject and How to Submit a Request

Under Article 11 of the Law, the data subject has the right to learn whether their personal data is being processed, to request information if it has been processed, to learn the purpose of processing and whether the data is used in accordance with that purpose, to know the third parties to whom the data is transferred in Türkiye or abroad, and to request the rectification of data processed incompletely or inaccurately.

The data subject may also exercise the rights to request the erasure or destruction of data within the conditions set out in Article 7 of the Law, to request that rectification and erasure operations be notified to the third parties to whom the data has been transferred, to object to an outcome adverse to them arising from analysis carried out exclusively by automated systems, and to claim compensation for damage suffered as a result of unlawful processing of the data.

Requests are submitted in writing or through a registered electronic mail address, secure electronic signature, mobile signature, or an email address previously notified to the data controller and recorded in its system, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller. The request must include the applicant's given name and surname, signature or electronic signature, Republic of Türkiye identity number (passport number for foreign nationals), address for service, email and telephone for notification if any, and the subject of the request.

Requests are concluded as soon as possible and in any event within thirty days, depending on their nature. Where the operation entails an additional cost, the fee set out in the tariff determined by the Board may be charged. If the request is refused, the response is found inadequate, or no response is given within the applicable period, the data subject may lodge a complaint with the Personal Data Protection Board within thirty days of learning of the response and, in any event, within sixty days of the date of application.

  • Request email: [To be completed before publication: KVKK request email address]
  • Registered electronic mail (KEP) address: [To be completed before publication]
  • Address for written applications: [To be completed before publication: head office address]
  • Link to the application form: [To be completed before publication: form file or page link]

9. Cookie Policy

Cookies and similar tracking technologies are used on our website. A cookie is a small text file placed on the browser by the site being visited. Essential cookies are required for the site to function and for its security; in line with the Personal Data Protection Authority's Guidelines on Cookie Practices, explicit consent is not sought for these, and the basis is Article 5(2)(c) or Article 5(2)(f) of the Law, depending on the specific case. Analytics and marketing cookies are activated only after the visitor's explicit consent has been obtained.

The site presents a cookie preference panel on the first visit. The visitor may accept or refuse non-essential cookies by category. Closing the panel or continuing to browse the site does not constitute consent; consent is obtained only through an express and separate choice. Consent given may be withdrawn at any time through the same panel. Withdrawal takes effect prospectively and does not render unlawful any processing carried out up to the date of withdrawal.

Cookies may also be deleted or blocked through browser settings. If essential cookies are blocked, functions such as form submission, session security, and language preference may not work. The table below summarizes cookie categories and consent status; the periods are indicative, and the name, provider, and duration of each individual cookie used are listed separately in the cookie preference panel.

CategoryFunctionConsent requiredTypical duration
EssentialSession management, security, form submission, load balancingNo (art. 5(2)(c) or art. 5(2)(f))Session duration up to 12 months
PreferenceLanguage and region selection, remembering panel preferencesNo (art. 5(2)(c) or art. 5(2)(f))6-12 months
AnalyticsVisit statistics, page performance, error trackingYes (explicit consent)12-24 months
MarketingRetargeting, campaign measurement, advertising identifiersYes (explicit consent)3-13 months
Cookie categories and consent status

10. Commercial Electronic Messages and İYS

Newsletters, announcements, and legislative updates are sent within the framework of the Law on the Regulation of Electronic Commerce (Elektronik Ticaretin Düzenlenmesi Hakkında Kanun) No. 6563 and the Regulation on Commercial Communication and Commercial Electronic Messages. No commercial electronic message is sent without the recipient's prior consent. Consent may be obtained through the Message Management System (İleti Yönetim Sistemi, İYS), in writing, or by any means of electronic communication, and is recorded in İYS.

The consent text clearly states the subject of the message and the sender's details. The recipient may refuse to receive messages at any time and without giving reasons. The right of refusal may be exercised through the link included in every message, through İYS, or through the communication channels set out in this notice. A notice of refusal is implemented within three business days of receipt and is recorded in İYS.

Transactional notifications sent within an ongoing service relationship are not treated as commercial electronic messages. Messages such as file status updates, appointment reminders, invoices, and official process notifications continue to be sent as part of the performance of the contract, even if marketing consent has been withdrawn.

  • Consent record: İYS brand details [To be completed before publication: İYS brand name and number]
  • Opt-out channel: the unsubscribe link included in every message
  • Opt-out channel: updating preferences directly through İYS
  • Opt-out channel: [To be completed before publication: email address for opt-out notices]

11. Data Security Measures

In accordance with Article 12 of the Law, administrative and technical measures are taken to ensure an appropriate level of security, with a view to preventing the unlawful processing of personal data and unlawful access to it, and to ensuring that data is preserved. Measures are determined by reference to the nature of the data processed and the magnitude of the harm that could arise, and are reviewed regularly.

On the technical side, communications are encrypted, access rights are limited to job descriptions, strong authentication is applied, log records are kept, and backup and up-to-date patch management are maintained. On the administrative side, confidentiality undertakings are signed with employees and business partners, contracts compliant with the Law are concluded with data processors, and the retention and destruction policy and the breach response procedure are kept in force.

Where a data breach is identified, notification is made to the Personal Data Protection Authority within seventy-two hours at the latest from becoming aware of the breach, and to the affected data subjects within the shortest reasonable time, in accordance with the fifth paragraph of Article 12 of the Law and the Board's decision No. 2019/10 dated January 24, 2019. The notification sets out the scope of the breach, its likely consequences, and the measures taken. Since no technical measure provides absolute security, users are also expected to take care of the security of their accounts and email.

12. Updates to This Notice and Entry into Force

This notice is updated in the event of changes in legislation, decisions of the Personal Data Protection Board, changes in the scope of services, or changes in the technical infrastructure used. The current version is always published on this page, and the effective date is stated at the foot of the notice. Where changes are material, notification is also given through the website.

The cross-border transfer regime is reviewed regularly in light of the amendments introduced by Law No. 7499 and the related secondary legislation. Where the Board announces new adequacy decisions, amends the standard contract texts, or updates the notification procedure, the transfer bases are updated and stated in this section. For countries without an adequacy decision, the appropriate safeguard routes continue to apply.

This notice does not replace the agreements governing the commercial terms of our services; it applies alongside them. Turkish law governs the interpretation and application of this notice. The headings used are for ease of reading only and do not limit the scope of the provisions.

  • Effective date: [To be completed before publication: dd.mm.yyyy]
  • Last updated: [To be completed before publication: dd.mm.yyyy]
  • Version: [To be completed before publication: e.g., v1.0]
FREQUENTLY ASKED

The questions we hear most on this

The answers below are deliberately direct. A process that starts with the wrong expectations ends badly for both of us.

Yes. In order to carry out company formation, residency permit, and bank account processes, data must be transferred to the affiliated legal entity in the UAE, to free zone authorities, to immigration authorities (GDRFA in Dubai, ICP in the other emirates), and to the relevant banks. The transfer is made in accordance with the order of priority set out in Article 9 of Law No. 6698 as amended by Law No. 7499: an adequacy decision; failing that, an appropriate safeguard (principally the standard contract); and where neither is possible, the derogations listed in that article, on an incidental basis only. Where the standard contract is used, it is notified to the Personal Data Protection Authority within five business days of signature.

Preliminary consultation and form records that do not convert into an engagement are retained for an indicative period of one year from the conclusion of the request and are then erased in the periodic destruction process. This period serves to preserve context should the same person get in touch again, and to evidence the correspondence in the event of a dispute. You may submit an erasure request before that period expires; if there is no legal ground requiring retention, the request is granted.

Yes. Analytics and marketing cookies are based solely on explicit consent, and that consent may be withdrawn at any time. You can update your choices by category through the cookie preference panel on the site, and you can also delete existing cookies through your browser settings. Withdrawal takes effect prospectively; it does not render unlawful any processing carried out up to the date of withdrawal. No consent is sought for essential cookies, because they are required for the site to function and for its security.

No. Withdrawing consent for commercial electronic messages covers marketing messages only. Transactional notifications such as file status updates, appointment reminders, official process notifications, and invoices continue to be sent as part of the performance of the contract and are not treated as commercial electronic messages. You can withdraw marketing consent through the unsubscribe link in every message or through İYS; a notice of refusal is implemented within three business days.

You may submit your request in writing, through a registered electronic mail address, secure electronic signature, mobile signature, or the email address you have previously notified to us and that is recorded in our system. The request must include your given name and surname, identity or passport number, address for service, and the subject of the request. Requests are concluded within thirty days at the latest. If the operation entails an additional cost, the fee set out in the Board's tariff may be charged. If you are not satisfied with the response, the route of complaint to the Board remains open.

No. The United Arab Emirates falls within the CRS framework for the automatic exchange of financial account information, and account information may reach Türkiye. In addition, notifications relating to capital exports by residents of Türkiye for the purpose of establishing a company abroad or acquiring a shareholding in an existing company continue to be made through the bank executing the transfer, in accordance with Decree No. 32 and the Central Bank of Türkiye Capital Movements Circular. Structuring an arrangement for the purpose of confidentiality is not realistic; the process is conducted on the basis of transparency. This answer is general information and does not constitute tax or legal advice.

Free Introductory CallWhatsApp