Legal

Privacy Policy

Last updated: [DATE — set on legal sign-off]

1. Who we are

This Privacy Policy explains how [full registered legal entity name, e.g. "iSoftStone Europe [Sp. z o.o. / Ltd / A.Ş.]"] ("iSoftStone Europe," "we," "us," or "our") collects, uses, discloses, and protects personal data when you visit isoftstone.eu (the "Site") or otherwise interact with us, such as by submitting a contact form or booking a meeting.

We are committed to protecting your privacy and handling your personal data in an open and transparent manner, in line with the EU General Data Protection Regulation (GDPR) and applicable local data protection law.

2. Data controller

The data controller responsible for your personal data is:

[Registered legal entity name]
[Registered address — confirm which office (Istanbul and/or Warsaw) is the correct GDPR-notice address for this entity]
Email: [privacy@isoftstone.eu or equivalent]

If we appoint a Data Protection Officer (DPO) or an EU representative under Article 27 GDPR, their contact details will be listed here: [DPO / EU representative contact, if applicable].

3. What personal data we collect

We collect personal data that you provide to us directly, primarily through the Site's contact form:

We may also collect limited technical data automatically when you browse the Site (e.g. IP address, browser type, pages visited, referring page) via cookies and similar technologies. This is described in full in our Cookie Policy.

We do not knowingly collect special categories of personal data (e.g. health, religious belief, political opinion) through the Site, and we ask that you do not include such data in the free-text fields of the contact form.

4. How and why we use your data (purposes and legal bases)

PurposeLegal basis (GDPR Art. 6)
Responding to your enquiry or meeting requestConsent (Art. 6(1)(a)) — given via the contact form's consent checkbox — and/or steps taken at your request prior to entering a contract (Art. 6(1)(b))
Maintaining business records of client and prospect communicationsLegitimate interests (Art. 6(1)(f)) — operating and growing our consultancy business
Site security, fraud prevention, and diagnosing technical issuesLegitimate interests (Art. 6(1)(f))
Analytics cookies (if enabled)Consent (Art. 6(1)(a)) — see Cookie Policy

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.

5. Who we share your data with

We do not sell your personal data. We may share it with:

6. International data transfers

iSoftStone Europe operates delivery teams in Türkiye and Poland. Poland is within the European Economic Area, so no additional transfer safeguard is required for data processed there. Türkiye is not currently subject to a European Commission adequacy decision; where personal data is transferred to or accessed from our Türkiye hub, we rely on Standard Contractual Clauses (SCCs) or another valid GDPR Chapter V transfer mechanism, together with appropriate technical and organizational safeguards. [confirm which specific safeguard/SCC set applies once the exact data flows to the Türkiye hub are mapped]

7. Data retention

We retain personal data submitted via the contact form for [retention period, e.g. "24 months from last contact" or per an internal records-retention schedule], after which it is deleted or anonymized, unless a longer retention period is required to comply with a legal obligation, resolve a dispute, or enforce our agreements.

8. Your rights

Under the GDPR, you have the right to:

To exercise any of these rights, contact us at [privacy@isoftstone.eu or equivalent]. You also have the right to lodge a complaint with your local data protection supervisory authority — for example, [the supervisory authority relevant to the controller's home jurisdiction, e.g. Poland's UODO or Türkiye's KVKK if applicable].

9. Cookies

The Site uses cookies and similar technologies. Full detail on the categories of cookies used, their purpose, and how to manage your preferences is set out in our Cookie Policy.

10. Children's privacy

The Site is intended for business audiences and is not directed at, or knowingly used to collect data from, children under 16.

11. Security

We apply appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, proportionate to the risk associated with the data we process.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "last updated" date at the top of this page indicates when it was last revised.

13. Contact us

Questions about this Privacy Policy or how we handle your personal data can be sent to [privacy@isoftstone.eu or equivalent], or by post to the address in Section 2 above.