1. Overview & Data Controller Identity
This Privacy Policy governs the processing of personal and business information by CorpiFind (“we”, “us”, or “our”), operating via corpifind.com. The platform is owned and operated by VARS SU ÜRÜNLERİ İTHALAT İHRACAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ, a commercial entity duly incorporated under the laws of the Republic of Türkiye.
CorpiFind operates as an evidence-first B2B trade intelligence platform facilitating direct procurement between international commercial buyers and licensed Turkish aquaculture, agriculture, and specialty food producers. Under Turkish Law No. 6698 (KVKK) and Regulation (EU) 2016/679 (GDPR), VARS Su Ürünleri İth. İhr. San. ve Tic. Ltd. Şti. acts as the statutory Data Controller in respect of personal and commercial data collected through your account registration, inquiries, and platform interactions.
Statutory Data Controller Office:
VARS SU ÜRÜNLERİ İTHALAT İHRACAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ
Tax Identification Number (VKN): 9240533729 (Konak Tax Office)
MERSİS Registration: 0924053372900001
Registered Headquarters: İsmet Kaptan Mah., Şair Eşref Blv. No:6 D:304/B, Konak, İzmir, 35210, Türkiye
Telephone: +90 232 290 57 56
Official Contact: [email protected] / [email protected]
Corporate Portal: https://varsco.com
2. Categories of Data Collected
In accordance with the principle of data minimisation (Article 5(1)(c) GDPR), we collect only information that is strictly necessary to deliver verified B2B trade intelligence and facilitate commercial matchmaking. We do not collect consumer consumer-credit data, consumer behavioural tracking profiles, or special categories of personal data (such as health, biometric, or political beliefs).
A. Account & Identity Information
When creating an account, we collect: full name, corporate email address, password hash (salted bcrypt cost 12), organisation name, country of business registration, and designated trade role (e.g., International Buyer, Turkish Producer, Customs Broker, Freight Forwarder).
B. Sourcing Specifications & RFQs
Commercial query parameters, commodity specifications (e.g., target calibers, moisture content, certifications like ASC/MSC/GlobalGAP), requested volume in metric tons, destination ports, target Incoterms (ICC 2020), and proforma invoice drafts.
C. Operational Security & Network Telemetry
Session cookies (cf_access andcf_refresh). Each session record stores the IP address and browser details (user agent) of the device that opened it. Security events such as sign-in attempts and password or account changes are written, with the IP address and browser details, to a security log that cannot be edited. Separately, IP addresses are counted in memory only, for at most 60 seconds, to rate-limit the API.
D. Public Institutional Registry Data
Company and facility records taken from official public sources (for example approval numbers). Some of these records may belong to natural persons (for example sole traders); in that case they are handled as personal data even though they are public.
3. Purposes & Lawful Bases for Processing
We process personal and corporate data under the following legal bases pursuant to Article 6 of the GDPR:
| Processing Purpose | Data Categories | GDPR Lawful Basis |
|---|---|---|
| Account provisioning and platform access | Name, email, password hash, company name | Contract (Art. 6(1)(b)) |
| B2B supplier matching and proforma packet drafting | Commercial RFQs, destination ports, Incoterms | Contract (Art. 6(1)(b)) |
| Platform security, rate limiting, and brute-force defence | In-memory IP address, session tokens, user-agent | Legitimate Interest (Art. 6(1)(f)) |
| Customs compliance verification and document notarisation | Facility approval numbers, SHA-256 trade hashes | Legal Obligation & Contract |
4. International Data Transfers (EU – Türkiye)
CorpiFind operates primarily at the intersection of the European Union Single Market, the United Kingdom, and the Republic of Türkiye. When personal or commercial data is transferred between these jurisdictions:
- Standard Contractual Clauses (SCCs): For transfers of personal data from the EU/EEA to infrastructure or suppliers located in Türkiye, we implement standard contractual safeguards approved by the European Commission under Article 46(2)(c) GDPR.
- Bilateral Trade Concessions: Communications regarding customs declarations are governed by European Community-Turkey Association Council Decision 1/95 (Customs Union) and Decision 1/98 (Agricultural Products Preferential Regime).
- Direct Contractual Performance: When an international buyer explicitly submits an RFQ to a Turkish producer, data transfer occurs directly in performance of commercial pre-contractual measures requested by the user (Article 49(1)(b) GDPR).
5. Data Retention & Erasure Mechanisms
We retain personal data only for as long as your account remains active or as required by applicable tax, customs, and statutory record-keeping obligations:
6. Technical & Cryptographic Safeguards
CorpiFind applies rigorous engineering controls to safeguard all data against unauthorized access, loss, or alteration:
- Transport Security: All web and API traffic is encrypted over HTTPS.
- Credential Hashing: Passwords hashed using bcrypt with work factor 12; raw passwords are never logged or stored.
- Cookie Security: Authentication cookies are configured with
httpOnly,SameSite=Lax, andSecureflags. - Cryptographic Document Verification: Issued commercial dossiers and proforma invoices can be sealed with SHA-256 cryptographic hashes for non-repudiation.
- Staff Access: The administration console runs on a separate domain with staff accounts kept apart from customer accounts. Every staff sign-in requires two-step verification (TOTP), and the verification secrets are stored encrypted with AES-256-GCM. What the console records about staff is set out in a separate staff privacy notice, shown on the console's sign-in page.
7. Your Rights under GDPR & Applicable Law
Under Articles 15 through 22 of the GDPR and equivalent international statutes, you have the following rights:
To exercise any of these rights, please contact our privacy desk at [email protected]. We respond to all verified requests within thirty (30) calendar days.
9. Contact & Supervisory Authorities
If you have questions, concerns, or complaints regarding this Privacy Policy or our data handling practices, please write to:
VARS Su Ürünleri İth. İhr. San. ve Tic. Ltd. Şti. — Data Protection Office
Email: [email protected] / [email protected]
Telephone: +90 232 290 57 56
Address: İsmet Kaptan Mah., Şair Eşref Blv. No:6 D:304/B, Konak, İzmir, 35210, Türkiye
You also have the right to lodge a complaint with an EU data protection supervisory authority (such as the DPC in Ireland, BfDI in Germany, or CNIL in France) or the Turkish Personal Data Protection Authority (KVKK Kurumu, Ankara).