
Privacy Policy and GDPR Information Text
Privacy Policy
Last updated: 5 August 2026
1. Data Controller
The data controller in relation to this website and the services offered through it is:
Sertaç Yay – Einzelunternehmen
Hartriegelstr. 130
12439 Berlin
Germany
Email: partnership@sertacyay.com
Website: https://www.sertacyay.com
This Privacy Policy has primarily been prepared in accordance with the EU General Data Protection Regulation (“GDPR/DSGVO”) and German data protection law. To the extent that services are provided to individuals located in Türkiye, it also includes information required under the Turkish Personal Data Protection Law No. 6698 (“KVKK”), where applicable.
2. What Personal Data Do We Process?
-
Account and identity data: First name, last name, email address, membership status, account ID, and login information.
-
Contact data: Telephone number, if provided, email address, contact form content, and support correspondence.
-
CV and career data: The complete CV file, information entered into form fields, free-text content, work experience, education, skills, achievements, language proficiency, and other content added by the user.
-
Job posting and AI usage data: Job postings entered by the user, questions, prompts, generated scores, feedback, and responses.
-
Contract and transaction data: Purchased products or services, subscription package, usage quota, appointments, event tickets, cancellations, withdrawals, and delivery records.
-
Payment data: Payment method, transaction status, amount, currency, billing information, and limited transaction identifiers provided by the payment provider. Full payment card details are generally processed by Stripe or PayPal and are not stored by us.
-
Technical and security data: IP address, date and time, device and browser information, session and security logs, essential cookies, and error logs.
-
Marketing preferences: Newsletter consent, date and source of consent, withdrawal of consent, and communication preferences.
-
Event images: Depending on the nature of the event, general photographs and video recordings of the event, as well as close-up images where separate consent has been provided.
3. For What Purposes and on What Legal Bases Do We Process Personal Data?
Account Creation and Membership
Purpose: To create the account and provide login functionality and security.
Legal basis: Article 6(1)(b) GDPR; processing necessary for entering into or performing a contract.
Retention: Until the account is deleted. Security records may be retained for a shorter period depending on operational requirements.
CV Storage and Tools
Purpose: To create, store, edit, score, and analyse CVs and provide interview preparation functionality.
Legal basis: Article 6(1)(b) GDPR.
Retention: Until the user deletes the CV or the account.
OpenAI-Assisted Analysis
Purpose: To analyse CVs and job postings and generate informational outputs.
Legal basis: Article 6(1)(b) GDPR; and, where necessary for security-related processing, Article 6(1)(f) GDPR.
Retention: If requests and outputs form part of the user's account on the website, they may be retained until the account is deleted. OpenAI's retention period may vary depending on the API feature used.
Sales and Payments
Purpose: Payment processing, invoicing, fraud prevention, delivery, and customer support.
Legal basis: Articles 6(1)(b), 6(1)(c), and, where applicable, 6(1)(f) GDPR.
Retention: Invoices and accounting records are generally retained for eight years; commercial correspondence is generally retained for six years.
Consulting and Appointments
Purpose: Appointment scheduling, providing the consultation, and managing cancellations and refunds.
Legal basis: Article 6(1)(b) GDPR.
Retention: Contract-related records are retained for the applicable statutory limitation and retention periods.
Events
Purpose: Ticketing, participant management, safety, and general documentation of events.
Legal basis: Articles 6(1)(b) and 6(1)(f) GDPR; Article 6(1)(a) GDPR for close-up images and images used for promotional purposes.
Retention: Ticketing and accounting records are retained for the applicable statutory period. Images are retained according to their intended purpose or until consent is withdrawn, where processing is based on consent.
Communications
Purpose: To respond to questions and manage requests and complaints.
Legal basis: Article 6(1)(b) or Article 6(1)(f) GDPR.
Retention: Generally three years after the request has been resolved, or longer where required by law.
Email Marketing
Purpose: To send announcements and offers to individuals who have provided their consent.
Legal basis: Article 6(1)(a) GDPR and applicable German unfair competition rules.
Retention: Until consent is withdrawn. Evidence of consent may be retained for the applicable legal defence period.
Essential Cookies
Purpose: To operate the website, user sessions, payment processes, and security functions.
Legal basis: Section 25(2) TDDDG; Article 6(1)(b) or Article 6(1)(f) GDPR.
Retention: For the duration of the session or for a limited period depending on the function of the relevant cookie.
4. CV and Artificial Intelligence Processing
For features including CV analysis, CV scoring, content suggestions, and interview preparation, the complete CV, job posting entered by the user, and relevant prompts may be transmitted to the OpenAI API. In this context, OpenAI acts as a data processor on our behalf.
According to OpenAI's published API data controls, data submitted through the API is not used to train models unless the customer expressly chooses to share such data for that purpose. Under standard API usage, prompts, responses, and related metadata may generally be retained for up to 30 days for abuse monitoring purposes. Certain API features may retain application data for longer periods, including until such data is deleted.
Artificial intelligence outputs are automated and probabilistic and may contain incorrect, incomplete, or contextually inappropriate results. Outputs are provided solely for informational and preparation purposes. Employment, interview success, or any specific result is not guaranteed. Users are responsible for reviewing outputs for accuracy and suitability for their intended use.
We do not make final decisions concerning users that produce legal or similarly significant effects based solely on automated processing.
Data minimisation: Users should not include health information, biometric data, political opinions, religious beliefs, trade union membership, identity or passport numbers, banking information, or unnecessary information concerning third parties in their CVs. Contact information for references should only be included where the user has the necessary authority or consent to do so.
5. Service Providers and Recipients
-
Wix Online Platform Limited and Wix group companies: Hosting, membership functionality, databases, file storage, appointments, ticketing, email services, and technical infrastructure.
-
OpenAI Ireland Ltd. and approved subprocessors: CV and job posting analysis and generation of AI outputs.
-
Stripe Payments Europe, Ltd. and relevant Stripe companies: Payment processing, fraud prevention, and payment records.
-
PayPal (Europe) S.à r.l. et Cie, S.C.A. and relevant PayPal companies: Payment processing, fraud prevention, and payment records.
-
Wix Email Marketing: Sending emails only to individuals who have separately provided consent and managing consent and communication preferences.
-
Accounting, legal, and IT security service providers and public authorities: Only where necessary and where an appropriate legal basis exists.
Personal data is not sold.
Depending on the relevant service, service providers may act either as independent data controllers in relation to their own services or as processors acting on our behalf. Independent processing activities carried out by payment providers are subject to their respective privacy policies.
6. International Data Transfers
Wix, OpenAI, Stripe, and PayPal may use global infrastructure.
Where personal data is processed outside Germany or the European Economic Area, mechanisms under Chapter V of the GDPR are used where applicable, including European Commission adequacy decisions, EU Standard Contractual Clauses, and supplementary security measures.
Users may review the relevant provider's current privacy policy and list of subprocessors on the provider's own website.
Where the KVKK applies to processing concerning individuals in Türkiye, international data transfers are additionally assessed under Article 9 of the KVKK and the relevant secondary legislation.
A user's direct provision of personal data to a data controller located in Germany and an international transfer made by a data exporter located in Türkiye are not necessarily the same type of processing activity.
Nevertheless, for ongoing activities involving Türkiye and subsequent transfers to service providers, the applicable international transfer mechanism should be confirmed with a Turkish data protection lawyer.
7. Cookies and Similar Technologies
The website is currently configured to use only those cookies that are necessary for the operation of Wix infrastructure and the functionalities requested by the user.
These cookies may be used for login functionality, security, load balancing, payment processing, remembering preferences, and essential website functions.
If non-essential analytics, advertising, or tracking tools are enabled in the future, they will not be activated before obtaining the user's consent, and the cookie panel and this Privacy Policy will be updated accordingly.
Cookies may be deleted or blocked through browser settings. Blocking essential cookies may prevent certain website functions from operating correctly.
8. Marketing Emails
Marketing emails are sent only to individuals who have separately provided their consent.
Consent to marketing communications is not a condition for purchasing a product or creating a membership.
Consent may be withdrawn at any time by using the unsubscribe link contained in each email or by contacting partnership@sertacyay.com.
Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
9. Account and CV Deletion and Data Retention
Accounts and stored CVs are retained until the user deletes them or closes their account.
Users may delete their CV through their account.
When an account is deleted, account and CV data that is no longer required for providing the service will be deleted or anonymised.
However, invoices, payment records, evidence of withdrawal and delivery, dispute records, and documents that must be retained due to legal obligations may be stored separately for the applicable statutory retention period.
10. Your Rights
Under the GDPR, you may have the following rights:
-
Right of access to your personal data
-
Right to rectification of inaccurate or incomplete personal data
-
Right to request deletion of your personal data
-
Right to restriction of processing
-
Right to data portability
-
Right to object to processing based on legitimate interests
-
Right to withdraw your consent
Where the KVKK applies, you may additionally have the following rights under Article 11 of the KVKK:
-
To learn whether your personal data is being processed
-
To request information regarding the processing of your personal data
-
To learn the purpose of processing and whether your personal data is being used in accordance with that purpose
-
To learn the third parties to whom your personal data has been transferred
-
To request correction of personal data that has been processed incompletely or inaccurately
-
To request deletion or destruction of your personal data
-
To object to a result arising against you as a result of analysis conducted exclusively through automated systems
-
To request compensation for damages arising from unlawful processing of personal data
You may submit your request to partnership@sertacyay.com or through the contact form available on the website.
We may request only such additional information as is necessary to verify your identity.
11. Right to Lodge a Complaint
Under the GDPR, you have the right to lodge a complaint in particular with the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), or with the competent supervisory authority in the place where you live or work.
Where the KVKK applies, you may also have the right to submit a complaint to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) in accordance with the applicable statutory application procedure.
12. Security, Children and Changes to This Policy
We implement reasonable technical and organisational measures designed to prevent unauthorised access, loss, alteration, and disclosure of personal data. Such measures may include access controls, account security measures, available encryption mechanisms, vendor management, and data minimisation.
However, no system can guarantee absolute security.
Account creation and purchases are intended only for individuals aged 18 or over. Persons under the age of 18 should not create an account or submit personal data through the website.
This Privacy Policy may be updated where our services, service providers, or applicable laws change.
Material changes will be communicated through an appropriate method, and the current version of this Privacy Policy will be published on this page.