Privacy Policy

This Privacy Policy explains how the Service Provider (“Provider”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards personal data of Clients and Beneficiaries (“you” or “your”) in connection with this Service Agreement.

We comply with the following data protection laws, depending on your jurisdiction:

European Economic Area: GDPR (Regulation (EU) 2016/679)

Turkey: Personal Data Protection Law No. 6698 (KVKK) as amended in 2024–2025

India: Digital Personal Data Protection Act, 2023 (DPDPA) and Digital Personal Data Protection Rules, 2025

Vietnam: Decree No. 13/2023/NĐ-CP (effective July 1, 2023) and Law on Personal Data Protection No. 91/2025/QH15 (effective January 1, 2026)

Philippines: Data Privacy Act of 2012 (R.A. 10173), its Implementing Rules and Regulations (IRR), and NPC issuances (including Circulars, Advisory Opinions, and Model Clauses)

For all other jurisdictions, we process personal data in accordance with generally accepted data protection principles and this Policy.

________________

1. DATA CONTROLLER

The Provider acts as the Data Controller (or Data Fiduciary under Indian law, or Personal Information Controller (PIC) under Philippine law, or Data Controller under Turkish/Vietnamese law).

Contact details:

Name: Shevtsov Artem Viktorovich

Email: info@deutscheragent.com

Address: Russia, Leningrad Oblast, Priozernoe village, building 27

________________

2. PERSONAL DATA WE COLLECT

We may collect the following categories of personal data:

Identifiers: full name, date of birth, nationality, passport/ID number (if required for Services)

Contact data: email address, phone number, messenger IDs (WhatsApp, Telegram, etc.), postal address

Professional/educational data: CV/resume, work history, qualifications, languages, interview-related information

Communications: emails, chat/messenger history, voice messages, consultation notes

Technical data: IP address, email metadata, messenger usage logs (only as necessary for delivery of Services)

Special categories (sensitive data): We do not intentionally collect health, biometric, political, or religious data unless strictly necessary for a specific Service and with your explicit consent. Under Indian law, such data requires additional notice and consent mechanisms.

________________

3. LEGAL BASES FOR PROCESSING

3.1 For all jurisdictions

We process your personal data for the following purposes:

Performance of the Service Agreement (providing consultations, preparing documents, communication)

Our legitimate interests (portfolio use in anonymized form, service improvement, fraud prevention)

Compliance with legal obligations (tax, anti-money laundering, court orders)

3.2 Specific requirements by country

Jurisdiction

Legal Basis / Specific Requirements

Turkey (KVKK)

Processing is based on: (a) explicit consent where required; (b) necessity for performance of the contract (Article 5(2)(c) KVKK); (c) legitimate interests (Article 5(2)(f) KVKK) provided no harm to your fundamental rights. For sensitive personal data (health, biometric, etc.), we rely on explicit consent or other grounds permitted under KVKK as amended in 2025.

India (DPDPA)

We process personal data only for lawful purposes after providing a noticein clear, plain language (as required by DPDPA Section 5 and DPDP Rules 2025). Consent is free, specific, informed, unconditional, and unambiguous with a clear option to withdraw. We do not process data of children (under 18) without verifiable parental consent.

Vietnam

Processing is based on: (a) consent of the data subject; (b) performance of the contract; (c) compliance with legal obligations. For cross-border transfers of Vietnamese citizens’ personal data, we prepare a Transfer Impact Assessment (Hồ sơ đánh giá tác động) as required by Decree 13/2023/NĐ-CP Article 25.

Philippines

Processing is based on: (a) consent of the data subject; (b) necessity for performance of the contract (DPA Section 12); (c) legitimate interests (DPA Section 13). For cross-border transfers, we ensure an adequate level of protection through contractual or other lawful means as required by DPA Section 21 and IRR Rule V.

________________

4. DATA SHARING AND DISCLOSURE

We may share your personal data with:

Third-party service providers (translators, notaries, IT platforms, email, cloud storage, messengers) as permitted under Clause 2.2.2 of the Agreement

Beneficiaries designated by you (Clause 1.7 of the Agreement) – only to the extent necessary

Law enforcement / courts – if required by applicable law

For Indian Data Principals: We do not engage Consent Managers at this time. Consent is obtained directly from you. We will notify you if this changes.

For Turkish Data Subjects: If we transfer your data abroad using Standard Contractual Clauses (SCCs) adopted by the KVKK Authority, we will notify the KVKK Authority within 5 business days of executing such SCCs.

For Vietnamese Data Subjects: Cross-border transfer of personal data of Vietnamese citizens requires:

Preparation of a Transfer Impact Assessment (Hồ sơ đánh giá tác động)

Retention of such assessment and submission to the Ministry of Public Security upon request

Consent from the data subject prior to transfer

Possible suspension of transfer if violations are found

For Philippine Data Subjects: Cross-border transfers are permitted subject to:

Ensuring an adequate level of protection (contractual or other lawful means)

Voluntary adoption of ASEAN Model Contractual Clauses or NPC-approved Standard Contractual Clauses

________________

5. CROSS-BORDER DATA TRANSFERS

5.1 Safeguards by jurisdiction

Jurisdiction

Safeguards Applied

Turkey

We use KVKK-approved Standard Contractual Clauses (SCCs) for transfers abroad and notify the KVKK Authority within 5 business days. You may request a copy of these safeguards.

India

Cross-border transfers are permitted only to countries not blacklisted by the Central Government. We will ensure compliance with any government restrictions on transfers outside India.

Vietnam

We prepare and maintain a Transfer Impact Assessment as required by Decree 13/2023/NĐ-CP Article 25 and the new Law on Personal Data Protection (effective January 1, 2026).

Philippines

We ensure an adequate level of protection through contractual safeguards. We may adopt NPC-approved Standard Contractual Clauses or ASEAN Model Contractual Clauses as guidance.

EU/EEA

We will ensure appropriate safeguards (e.g., Standard Contractual Clauses) if we transfer data outside the EEA.

________________

6. DATA RETENTION

We retain your personal data only as long as necessary for:

Performing the Services and this Agreement

Compliance with legal obligations (e.g., tax records – 5 years)

Defense of legal claims

Specific retention requirements:

Jurisdiction

Retention Requirement

India

Retention period is as specified in the notice provided to you. Data must be erased upon request or when no longer needed, with 48-hour advance notice for erasure due to obsolescence.

Philippines

Retention is subject to the Data Sharing Agreement or Data Processing Agreement. Records of consent must be kept for as long as necessary to prove compliance.

Turkey

Retention periods are determined based on the purpose of processing. Upon expiry of the retention period, data is deleted, destroyed, or anonymized.

After the required period, data is securely deleted or anonymized.

________________

7. YOUR RIGHTS

7.1 Rights by jurisdiction

Right

India (DPDPA)

Turkey (KVKK)

Vietnam

Philippines (DPA)

Right to access

Yes – obtain summary of data and processing activities

Yes – learn whether data is processed

Yes – access personal data

Yes – reasonable access

Right to correction

Yes – correction, completion, updating

Yes – correction of incomplete/inaccurate data

Yes – update personal data

Yes – rectification

Right to erasure

Yes – with 48-hour notice for obsolescence

Yes – deletion/destruction under KVKK Article 7

Yes – erasure

Yes – erasure or blocking

Right to withdraw consent

Yes – as easy as giving consent

Yes – withdrawal of consent

Yes – withdraw consent

Yes – withdraw consent

Right to object

Yes – to processing based on legitimate interests

Yes – to negative result of automated processing

Yes – object to certain processing

Yes – object to processing

Right to data portability

Not explicitly provided

Not explicitly provided

Not explicitly provided

Yes – data portability (subject to conditions)

Right to grievance redressal

Yes – 90-day resolution timeline

Yes – complaint to KVKK Authority

Yes – complaint to relevant authority

Yes – complaint to NPC

Right to nominate representative

Yes – nominate a representative

Not explicitly provided

Not explicitly provided

Not explicitly provided

7.2 How to exercise your rights

To exercise your rights, contact us at info@deutscheragent.com. We will respond within the following timelines:

India: Within a reasonable time (specific timeline to be prescribed)

Turkey: Within the timelines set by KVKK (generally 30 days)

Vietnam: Within the timelines set by applicable decrees

Philippines: Within a reasonable period (NPC expects prompt action)

EU/EEA: Within 30 days (extendable by 60 days where complex)

________________

8. SECURITY MEASURES

We implement reasonable technical and organizational measures to protect your data, including:

Encryption of email and communications where feasible

Access restrictions based on need-to-know

Regular security assessments

For Indian Data Principals: We implement reasonable security safeguards as required by DPDPA Section 8(5), including encryption, access control, logging, and breach detection mechanisms. Logs are retained for at least one year.

For Turkish Data Subjects: We implement appropriate security measures as required by KVKK Article 12 to prevent unlawful processing and unauthorized access.

For Philippine Data Subjects: We implement organizational, physical, and technical security measures as required by NPC Circular 16-01, including encryption in transit and at rest (AES-256 or equivalent), role-based access, and audit logs.

________________

9. DATA BREACH NOTIFICATION

In case of a personal data breach affecting your data:

Jurisdiction

Notification Requirement

India

We will notify affected Data Principals and the Data Protection Board of India within 72 hours of becoming aware of the breach.

Turkey

We will notify the KVKK Authority within 72 hours of discovery and, where required, notify affected data subjects.

Vietnam

We will notify the Ministry of Public Security within 72 hours of detecting a cross-border data transfer violation, as required by Decree 13/2023/NĐ-CP.

Philippines

We will notify the NPC and affected data subjects within 72 hours of knowledge of the breach, as required by NPC Circulars.

EU/EEA

We will notify the supervisory authority within 72 hours (if feasible).

________________

10. DATA PROTECTION OFFICER (DPO)

We have appointed a Data Protection Officer who can be contacted at:

DPO Email: info@deutscheragent.com

For Indian Data Principals: If we are classified as a Significant Data Fiduciary (SDF) by the Central Government, we will appoint a Data Protection Officer based in India as required. You will be notified of any such designation.

For Turkish Data Subjects: We have registered with VERBIS (Data Controllers’ Registry) as required under KVKK Article 16. Our VERBIS registration number is available upon request.

For Philippine Data Subjects: Our DPO is registered with the NPC as required. Our DPO’s contact details are provided above.

________________

11. GRIEVANCE REDRESSAL (INDIA ONLY)

Under the DPDPA and DPDP Rules 2025, we have established a grievance redressal mechanism.

Grievance Officer (India):

Name: Shevtsov Artem Viktorovich

Email: info@deutscheragent.com

Response timeline: We will acknowledge your grievance within 24 hours and resolve it within 90 days of receipt.

If you are not satisfied with our resolution, you may file a complaint with the Data Protection Board of India.

________________

12. CHILDREN’S DATA

Our Services are not directed to individuals under 18 years of age.

For Indian Data Principals: We do not process personal data of children (under 18) without verifiable parental consent as required by DPDPA Section 9 and DPDP Rules 2025. We implement appropriate technical and organizational measures to verify consent.

For Philippine Data Subjects: We comply with NPC guidelines on child-oriented transparency, including providing clear, age-appropriate information about data processing.

For Turkish Data Subjects: Processing of children’s data requires explicit consent from parental authority holders under KVKK.

________________

13. AUTOMATED DECISION-MAKING AND PROFILING

We do not engage in automated decision-making or profiling that produces legal effects concerning you.

For Philippine Data Subjects: If we introduce such processing, we will notify you as required by NPC guidelines on automated decision-making.

For Turkish Data Subjects: You have the right to object to the occurrence of a result against you through automated processing (KVKK Article 11(1)(g)).

________________

14. CONTACT FOR PRIVACY MATTERS

For all privacy-related inquiries, including exercising your rights, please contact:

Email: info@deutscheragent.com

Postal address: Russia, Leningrad Oblast, Priozernoe village, building 27

For Indian Data Principals: You may also contact our Grievance Officer (Section 12 above).

For Turkish Data Subjects: You may file a complaint with the KVKK Authority at www.kvkk.gov.tr.

For Philippine Data Subjects: You may file a complaint with the National Privacy Commission (NPC) at https://privacy.gov.ph.