Privacy Policy
This Privacy Policy explains how the Service Provider (“Provider”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards personal data of Clients and Beneficiaries (“you” or “your”) in connection with this Service Agreement.
We comply with the following data protection laws, depending on your jurisdiction:
European Economic Area: GDPR (Regulation (EU) 2016/679)
Turkey: Personal Data Protection Law No. 6698 (KVKK) as amended in 2024–2025
India: Digital Personal Data Protection Act, 2023 (DPDPA) and Digital Personal Data Protection Rules, 2025
Vietnam: Decree No. 13/2023/NĐ-CP (effective July 1, 2023) and Law on Personal Data Protection No. 91/2025/QH15 (effective January 1, 2026)
Philippines: Data Privacy Act of 2012 (R.A. 10173), its Implementing Rules and Regulations (IRR), and NPC issuances (including Circulars, Advisory Opinions, and Model Clauses)
For all other jurisdictions, we process personal data in accordance with generally accepted data protection principles and this Policy.
________________
1. DATA CONTROLLER
The Provider acts as the Data Controller (or Data Fiduciary under Indian law, or Personal Information Controller (PIC) under Philippine law, or Data Controller under Turkish/Vietnamese law).
Contact details:
Name: Shevtsov Artem Viktorovich
Email: info@deutscheragent.com
Address: Russia, Leningrad Oblast, Priozernoe village, building 27
________________
2. PERSONAL DATA WE COLLECT
We may collect the following categories of personal data:
Identifiers: full name, date of birth, nationality, passport/ID number (if required for Services)
Contact data: email address, phone number, messenger IDs (WhatsApp, Telegram, etc.), postal address
Professional/educational data: CV/resume, work history, qualifications, languages, interview-related information
Communications: emails, chat/messenger history, voice messages, consultation notes
Technical data: IP address, email metadata, messenger usage logs (only as necessary for delivery of Services)
Special categories (sensitive data): We do not intentionally collect health, biometric, political, or religious data unless strictly necessary for a specific Service and with your explicit consent. Under Indian law, such data requires additional notice and consent mechanisms.
________________
3. LEGAL BASES FOR PROCESSING
3.1 For all jurisdictions
We process your personal data for the following purposes:
Performance of the Service Agreement (providing consultations, preparing documents, communication)
Our legitimate interests (portfolio use in anonymized form, service improvement, fraud prevention)
Compliance with legal obligations (tax, anti-money laundering, court orders)
3.2 Specific requirements by country
Jurisdiction
Legal Basis / Specific Requirements
Turkey (KVKK)
Processing is based on: (a) explicit consent where required; (b) necessity for performance of the contract (Article 5(2)(c) KVKK); (c) legitimate interests (Article 5(2)(f) KVKK) provided no harm to your fundamental rights. For sensitive personal data (health, biometric, etc.), we rely on explicit consent or other grounds permitted under KVKK as amended in 2025.
India (DPDPA)
We process personal data only for lawful purposes after providing a noticein clear, plain language (as required by DPDPA Section 5 and DPDP Rules 2025). Consent is free, specific, informed, unconditional, and unambiguous with a clear option to withdraw. We do not process data of children (under 18) without verifiable parental consent.
Vietnam
Processing is based on: (a) consent of the data subject; (b) performance of the contract; (c) compliance with legal obligations. For cross-border transfers of Vietnamese citizens’ personal data, we prepare a Transfer Impact Assessment (Hồ sơ đánh giá tác động) as required by Decree 13/2023/NĐ-CP Article 25.
Philippines
Processing is based on: (a) consent of the data subject; (b) necessity for performance of the contract (DPA Section 12); (c) legitimate interests (DPA Section 13). For cross-border transfers, we ensure an adequate level of protection through contractual or other lawful means as required by DPA Section 21 and IRR Rule V.
________________
4. DATA SHARING AND DISCLOSURE
We may share your personal data with:
Third-party service providers (translators, notaries, IT platforms, email, cloud storage, messengers) as permitted under Clause 2.2.2 of the Agreement
Beneficiaries designated by you (Clause 1.7 of the Agreement) – only to the extent necessary
Law enforcement / courts – if required by applicable law
For Indian Data Principals: We do not engage Consent Managers at this time. Consent is obtained directly from you. We will notify you if this changes.
For Turkish Data Subjects: If we transfer your data abroad using Standard Contractual Clauses (SCCs) adopted by the KVKK Authority, we will notify the KVKK Authority within 5 business days of executing such SCCs.
For Vietnamese Data Subjects: Cross-border transfer of personal data of Vietnamese citizens requires:
Preparation of a Transfer Impact Assessment (Hồ sơ đánh giá tác động)
Retention of such assessment and submission to the Ministry of Public Security upon request
Consent from the data subject prior to transfer
Possible suspension of transfer if violations are found
For Philippine Data Subjects: Cross-border transfers are permitted subject to:
Ensuring an adequate level of protection (contractual or other lawful means)
Voluntary adoption of ASEAN Model Contractual Clauses or NPC-approved Standard Contractual Clauses
________________
5. CROSS-BORDER DATA TRANSFERS
5.1 Safeguards by jurisdiction
Jurisdiction
Safeguards Applied
Turkey
We use KVKK-approved Standard Contractual Clauses (SCCs) for transfers abroad and notify the KVKK Authority within 5 business days. You may request a copy of these safeguards.
India
Cross-border transfers are permitted only to countries not blacklisted by the Central Government. We will ensure compliance with any government restrictions on transfers outside India.
Vietnam
We prepare and maintain a Transfer Impact Assessment as required by Decree 13/2023/NĐ-CP Article 25 and the new Law on Personal Data Protection (effective January 1, 2026).
Philippines
We ensure an adequate level of protection through contractual safeguards. We may adopt NPC-approved Standard Contractual Clauses or ASEAN Model Contractual Clauses as guidance.
EU/EEA
We will ensure appropriate safeguards (e.g., Standard Contractual Clauses) if we transfer data outside the EEA.
________________
6. DATA RETENTION
We retain your personal data only as long as necessary for:
Performing the Services and this Agreement
Compliance with legal obligations (e.g., tax records – 5 years)
Defense of legal claims
Specific retention requirements:
Jurisdiction
Retention Requirement
India
Retention period is as specified in the notice provided to you. Data must be erased upon request or when no longer needed, with 48-hour advance notice for erasure due to obsolescence.
Philippines
Retention is subject to the Data Sharing Agreement or Data Processing Agreement. Records of consent must be kept for as long as necessary to prove compliance.
Turkey
Retention periods are determined based on the purpose of processing. Upon expiry of the retention period, data is deleted, destroyed, or anonymized.
After the required period, data is securely deleted or anonymized.
________________
7. YOUR RIGHTS
7.1 Rights by jurisdiction
Right
India (DPDPA)
Turkey (KVKK)
Vietnam
Philippines (DPA)
Right to access
Yes – obtain summary of data and processing activities
Yes – learn whether data is processed
Yes – access personal data
Yes – reasonable access
Right to correction
Yes – correction, completion, updating
Yes – correction of incomplete/inaccurate data
Yes – update personal data
Yes – rectification
Right to erasure
Yes – with 48-hour notice for obsolescence
Yes – deletion/destruction under KVKK Article 7
Yes – erasure
Yes – erasure or blocking
Right to withdraw consent
Yes – as easy as giving consent
Yes – withdrawal of consent
Yes – withdraw consent
Yes – withdraw consent
Right to object
Yes – to processing based on legitimate interests
Yes – to negative result of automated processing
Yes – object to certain processing
Yes – object to processing
Right to data portability
Not explicitly provided
Not explicitly provided
Not explicitly provided
Yes – data portability (subject to conditions)
Right to grievance redressal
Yes – 90-day resolution timeline
Yes – complaint to KVKK Authority
Yes – complaint to relevant authority
Yes – complaint to NPC
Right to nominate representative
Yes – nominate a representative
Not explicitly provided
Not explicitly provided
Not explicitly provided
7.2 How to exercise your rights
To exercise your rights, contact us at info@deutscheragent.com. We will respond within the following timelines:
India: Within a reasonable time (specific timeline to be prescribed)
Turkey: Within the timelines set by KVKK (generally 30 days)
Vietnam: Within the timelines set by applicable decrees
Philippines: Within a reasonable period (NPC expects prompt action)
EU/EEA: Within 30 days (extendable by 60 days where complex)
________________
8. SECURITY MEASURES
We implement reasonable technical and organizational measures to protect your data, including:
Encryption of email and communications where feasible
Access restrictions based on need-to-know
Regular security assessments
For Indian Data Principals: We implement reasonable security safeguards as required by DPDPA Section 8(5), including encryption, access control, logging, and breach detection mechanisms. Logs are retained for at least one year.
For Turkish Data Subjects: We implement appropriate security measures as required by KVKK Article 12 to prevent unlawful processing and unauthorized access.
For Philippine Data Subjects: We implement organizational, physical, and technical security measures as required by NPC Circular 16-01, including encryption in transit and at rest (AES-256 or equivalent), role-based access, and audit logs.
________________
9. DATA BREACH NOTIFICATION
In case of a personal data breach affecting your data:
Jurisdiction
Notification Requirement
India
We will notify affected Data Principals and the Data Protection Board of India within 72 hours of becoming aware of the breach.
Turkey
We will notify the KVKK Authority within 72 hours of discovery and, where required, notify affected data subjects.
Vietnam
We will notify the Ministry of Public Security within 72 hours of detecting a cross-border data transfer violation, as required by Decree 13/2023/NĐ-CP.
Philippines
We will notify the NPC and affected data subjects within 72 hours of knowledge of the breach, as required by NPC Circulars.
EU/EEA
We will notify the supervisory authority within 72 hours (if feasible).
________________
10. DATA PROTECTION OFFICER (DPO)
We have appointed a Data Protection Officer who can be contacted at:
DPO Email: info@deutscheragent.com
For Indian Data Principals: If we are classified as a Significant Data Fiduciary (SDF) by the Central Government, we will appoint a Data Protection Officer based in India as required. You will be notified of any such designation.
For Turkish Data Subjects: We have registered with VERBIS (Data Controllers’ Registry) as required under KVKK Article 16. Our VERBIS registration number is available upon request.
For Philippine Data Subjects: Our DPO is registered with the NPC as required. Our DPO’s contact details are provided above.
________________
11. GRIEVANCE REDRESSAL (INDIA ONLY)
Under the DPDPA and DPDP Rules 2025, we have established a grievance redressal mechanism.
Grievance Officer (India):
Name: Shevtsov Artem Viktorovich
Email: info@deutscheragent.com
Response timeline: We will acknowledge your grievance within 24 hours and resolve it within 90 days of receipt.
If you are not satisfied with our resolution, you may file a complaint with the Data Protection Board of India.
________________
12. CHILDREN’S DATA
Our Services are not directed to individuals under 18 years of age.
For Indian Data Principals: We do not process personal data of children (under 18) without verifiable parental consent as required by DPDPA Section 9 and DPDP Rules 2025. We implement appropriate technical and organizational measures to verify consent.
For Philippine Data Subjects: We comply with NPC guidelines on child-oriented transparency, including providing clear, age-appropriate information about data processing.
For Turkish Data Subjects: Processing of children’s data requires explicit consent from parental authority holders under KVKK.
________________
13. AUTOMATED DECISION-MAKING AND PROFILING
We do not engage in automated decision-making or profiling that produces legal effects concerning you.
For Philippine Data Subjects: If we introduce such processing, we will notify you as required by NPC guidelines on automated decision-making.
For Turkish Data Subjects: You have the right to object to the occurrence of a result against you through automated processing (KVKK Article 11(1)(g)).
________________
14. CONTACT FOR PRIVACY MATTERS
For all privacy-related inquiries, including exercising your rights, please contact:
Email: info@deutscheragent.com
Postal address: Russia, Leningrad Oblast, Priozernoe village, building 27
For Indian Data Principals: You may also contact our Grievance Officer (Section 12 above).
For Turkish Data Subjects: You may file a complaint with the KVKK Authority at www.kvkk.gov.tr.
For Philippine Data Subjects: You may file a complaint with the National Privacy Commission (NPC) at https://privacy.gov.ph.