Sign in
Data Protection & PrivacyRef: CORP-LEGAL-2026

Privacy Policy

How CorpiFind collects, processes, and protects corporate and personal data across our international B2B trade intelligence platform in compliance with GDPR and international data standards.

Last Updated:22 September 2026
Effective Date:22 September 2026
Jurisdiction:Türkiye & EU/EEA

1. Overview & Data Controller Identity

This Privacy Policy governs the processing of personal and business information by CorpiFind (“we”, “us”, or “our”), operating via corpifind.com. The platform is owned and operated by VARS SU ÜRÜNLERİ İTHALAT İHRACAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ, a commercial entity duly incorporated under the laws of the Republic of Türkiye.

CorpiFind operates as an evidence-first B2B trade intelligence platform facilitating direct procurement between international commercial buyers and licensed Turkish aquaculture, agriculture, and specialty food producers. Under Turkish Law No. 6698 (KVKK) and Regulation (EU) 2016/679 (GDPR), VARS Su Ürünleri İth. İhr. San. ve Tic. Ltd. Şti. acts as the statutory Data Controller in respect of personal and commercial data collected through your account registration, inquiries, and platform interactions.

Statutory Data Controller Office:

VARS SU ÜRÜNLERİ İTHALAT İHRACAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ

Tax Identification Number (VKN): 9240533729 (Konak Tax Office)

MERSİS Registration: 0924053372900001

Registered Headquarters: İsmet Kaptan Mah., Şair Eşref Blv. No:6 D:304/B, Konak, İzmir, 35210, Türkiye

Telephone: +90 232 290 57 56

Official Contact: [email protected] / [email protected]

Corporate Portal: https://varsco.com

2. Categories of Data Collected

In accordance with the principle of data minimisation (Article 5(1)(c) GDPR), we collect only information that is strictly necessary to deliver verified B2B trade intelligence and facilitate commercial matchmaking. We do not collect consumer consumer-credit data, consumer behavioural tracking profiles, or special categories of personal data (such as health, biometric, or political beliefs).

A. Account & Identity Information

When creating an account, we collect: full name, corporate email address, password hash (salted bcrypt cost 12), organisation name, country of business registration, and designated trade role (e.g., International Buyer, Turkish Producer, Customs Broker, Freight Forwarder).

B. Sourcing Specifications & RFQs

Commercial query parameters, commodity specifications (e.g., target calibers, moisture content, certifications like ASC/MSC/GlobalGAP), requested volume in metric tons, destination ports, target Incoterms (ICC 2020), and proforma invoice drafts.

C. Operational Security & Network Telemetry

Session cookies (cf_access andcf_refresh). Each session record stores the IP address and browser details (user agent) of the device that opened it. Security events such as sign-in attempts and password or account changes are written, with the IP address and browser details, to a security log that cannot be edited. Separately, IP addresses are counted in memory only, for at most 60 seconds, to rate-limit the API.

D. Public Institutional Registry Data

Company and facility records taken from official public sources (for example approval numbers). Some of these records may belong to natural persons (for example sole traders); in that case they are handled as personal data even though they are public.

3. Purposes & Lawful Bases for Processing

We process personal and corporate data under the following legal bases pursuant to Article 6 of the GDPR:

Processing PurposeData CategoriesGDPR Lawful Basis
Account provisioning and platform accessName, email, password hash, company nameContract (Art. 6(1)(b))
B2B supplier matching and proforma packet draftingCommercial RFQs, destination ports, IncotermsContract (Art. 6(1)(b))
Platform security, rate limiting, and brute-force defenceIn-memory IP address, session tokens, user-agentLegitimate Interest (Art. 6(1)(f))
Customs compliance verification and document notarisationFacility approval numbers, SHA-256 trade hashesLegal Obligation & Contract

4. International Data Transfers (EU – Türkiye)

CorpiFind operates primarily at the intersection of the European Union Single Market, the United Kingdom, and the Republic of Türkiye. When personal or commercial data is transferred between these jurisdictions:

  • Standard Contractual Clauses (SCCs): For transfers of personal data from the EU/EEA to infrastructure or suppliers located in Türkiye, we implement standard contractual safeguards approved by the European Commission under Article 46(2)(c) GDPR.
  • Bilateral Trade Concessions: Communications regarding customs declarations are governed by European Community-Turkey Association Council Decision 1/95 (Customs Union) and Decision 1/98 (Agricultural Products Preferential Regime).
  • Direct Contractual Performance: When an international buyer explicitly submits an RFQ to a Turkish producer, data transfer occurs directly in performance of commercial pre-contractual measures requested by the user (Article 49(1)(b) GDPR).

5. Data Retention & Erasure Mechanisms

We retain personal data only for as long as your account remains active or as required by applicable tax, customs, and statutory record-keeping obligations:

Account Profiles:Kept while the account is active. When you delete your account in your settings, your profile, sessions, saved cases, RFQs and proformas are deleted at once.
Authentication Sessions:Refresh tokens last 30 days with “remember me”, otherwise 12 hours, and stop working at once on sign-out or password reset. Expired session records (including IP address and browser details) are deleted by an hourly clean-up; revoked ones 7 days after revocation.
Security Log:Security events (sign-in attempts, password and account changes, account deletion, data exports) are written with the IP address and browser details to a log that cannot be edited, and kept for 24 months. After 24 months the IP address, browser details and identifiers are removed from each entry; the event itself remains. When you delete your account, what identifies you is removed from this log at once; where a staff member acted on your account, that staff member stays named in the entry, for accountability.
Network Rate Limits:In-memory IP buckets automatically expire and flush every 60 seconds.
Notarised Trade Hashes:Cryptographic SHA-256 digests contain zero reversible personal data and are maintained for verification integrity.

6. Technical & Cryptographic Safeguards

CorpiFind applies rigorous engineering controls to safeguard all data against unauthorized access, loss, or alteration:

  • Transport Security: All web and API traffic is encrypted over HTTPS.
  • Credential Hashing: Passwords hashed using bcrypt with work factor 12; raw passwords are never logged or stored.
  • Cookie Security: Authentication cookies are configured with httpOnly, SameSite=Lax, and Secure flags.
  • Cryptographic Document Verification: Issued commercial dossiers and proforma invoices can be sealed with SHA-256 cryptographic hashes for non-repudiation.
  • Staff Access: The administration console runs on a separate domain with staff accounts kept apart from customer accounts. Every staff sign-in requires two-step verification (TOTP), and the verification secrets are stored encrypted with AES-256-GCM. What the console records about staff is set out in a separate staff privacy notice, shown on the console's sign-in page.

7. Your Rights under GDPR & Applicable Law

Under Articles 15 through 22 of the GDPR and equivalent international statutes, you have the following rights:

Right to Access (Art. 15):Request confirmation of processing and obtain a copy of your personal data held by CorpiFind.
Right to Rectification (Art. 16):Correct inaccurate or incomplete business profile and contact information.
Right to Erasure (Art. 17):Request complete deletion of your user account and associated personal information (“Right to be Forgotten”).
Right to Data Portability (Art. 20):Download your data as a JSON file from your account settings: your profile, saved cases, RFQs, proformas, session records, and the security-log entries about you. Where someone else acted in an entry (for example a staff member), only the kind of actor is shown, never their identity, IP address or browser details.

To exercise any of these rights, please contact our privacy desk at [email protected]. We respond to all verified requests within thirty (30) calendar days.

8. Cookies & Telemetry

We strictly limit cookie usage to essential session tokens (cf_access, cf_refresh) and language preferences. We do not participate in cross-site tracking networks or sell corporate customer data to data brokers. Please review our full Cookie Policy for detailed disclosures.

9. Contact & Supervisory Authorities

If you have questions, concerns, or complaints regarding this Privacy Policy or our data handling practices, please write to:

VARS Su Ürünleri İth. İhr. San. ve Tic. Ltd. Şti. — Data Protection Office

Email: [email protected] / [email protected]

Telephone: +90 232 290 57 56

Address: İsmet Kaptan Mah., Şair Eşref Blv. No:6 D:304/B, Konak, İzmir, 35210, Türkiye

You also have the right to lodge a complaint with an EU data protection supervisory authority (such as the DPC in Ireland, BfDI in Germany, or CNIL in France) or the Turkish Personal Data Protection Authority (KVKK Kurumu, Ankara).