Yükleniyor...
Yükleniyor...
Boğaziçi University, DIGI4AGE European Digital Innovation Hub · Project Website: Contact Persons of SMEs, Collaborating Organisations and Service Providers
This English text is provided for convenience. The Turkish version is the legally binding text under Law No. 6698 on the Protection of Personal Data of the Republic of Türkiye (“KVKK”); in case of discrepancy, the Turkish version prevails. KVKK is the law governing this processing. In addition, as required by Article 15.2 of the Grant Agreement, the University applies the data-protection principles set out in that Article (lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation and security) to all personal data processed under the Project.
This privacy notice has been prepared pursuant to Article 10 of KVKK and the Communiqué on the Procedures and Principles for Fulfilling the Obligation to Inform, in order to inform natural persons who complete the application, registration, service request and contact forms on the website of DIGI4AGE (European Digital Innovation Hub for Healthy Living and Aging; Digital Europe Programme, Grant Agreement No. 101300776; “DIGI4AGE” or the “Project”).
The data controller in respect of your personal data is Boğaziçi University (the “University”), coordinator of the DIGI4AGE Consortium. DIGI4AGE is a project carried out under a Consortium Agreement concluded between the Consortium partners and has no separate legal personality.
| Field | Information |
|---|---|
| Name | Boğaziçi University (public university with public legal personality, established by Law No. 1487; Official Gazette No. 13954, 12 September 1971) |
| Address | Boğaziçi University, 34342 Bebek / Istanbul, Türkiye |
| Telephone | +90 212 359 54 00 |
| info@bogazici.edu.tr; Project: info@digi4age.com | |
| KEP (registered e-mail) | bogaziciuniversitesi@hs01.kep.tr |
| Website | https://bogazici.edu.tr/; Project: https://digi4age.com |
| KVKK policy documents | Boğaziçi University Policy on the Protection and Processing of Personal Data; Personal Data Retention and Destruction Policy (https://bogazici.edu.tr/tr/pages/kisisel-verilerin-korunmasi/155) |
Who is covered by this notice? Representatives and contact persons (natural persons) of SMEs, collaborating institutions/organisations and service providers who complete the forms on the Project website. Information relating to legal entities (business data such as trade name, tax number, sector, number of employees) does not constitute personal data under KVKK; however, in the case of sole proprietorships, business information may overlap with the personal data of the owner and is then protected as personal data.
Role of the Consortium partners. Consortium partners to whom your data are transferred for service delivery act as separate data controllers in respect of the data transferred to them and fulfil their own information obligations where required. Suppliers providing technical services on behalf of the University (hosting, cloud, form/CRM infrastructure) act as data processors under the University’s instructions.
| Category | Examples | Source |
|---|---|---|
| Identity | Name, surname | Form / data subject |
| Contact | Business e-mail, business telephone, business address | Form / data subject |
| Professional information | Organisation represented, position/title, authority to represent | Form / data subject |
| Application and service information | Service requested, content of application, digital maturity assessment (DMA) responses, service records, event participation, feedback | Form, service processes, Consortium partners |
| Legal transaction | Signature on service agreement/undertaking | Form, service processes |
| Transaction security | IP address, date and time of form submission, system logs, cookie identifiers | Website (automatic) |
| Audio-visual records | Photographs and video recordings taken at events (notified separately at the event) | Project events |
| Marketing preferences | Electronic message permission and preference records | Form / data subject |
Special categories of personal data (health, religion, trade union membership, biometric data, etc.) are neither requested nor processed. Please do not enter or upload such data in the forms or attachments. If you provide personal data of third parties (e.g. other contact persons of your organisation), you are responsible for informing those persons of this notice.
Your personal data are collected through the electronic forms on the Project website, e-mail and telephone communication, online meetings, Project events, digital maturity assessment and service delivery processes, and documents and information received from Consortium partners and competent authorities; by fully or partially automated means, or by non-automated means provided that the data form part of a data filing system.
Your personal data are processed on the legal grounds under Article 5 of KVKK indicated for each purpose in the table below. Your consent is not required for processing other than the purposes marked “explicit consent”; consent-based processing is carried out only through a separate consent declaration for each purpose and only if you give consent.
| Purpose | Description | Legal ground (KVKK Art. 5) |
|---|---|---|
| Receipt of applications and eligibility assessment | Receiving the service application, checking SME status and programme eligibility, preliminary interview | Art. 5(2)(c): processing necessary prior to conclusion of a contract |
| Delivery of DIGI4AGE services | Planning, delivering and monitoring digital maturity assessment, test-before-invest, skills development and training, support to access finance, ecosystem and networking services | Art. 5(2)(c): performance of a contract |
| Coordination within the Consortium | Routing the request to the Consortium partner delivering the service, service follow-up, quality evaluation | Art. 5(2)(c); Art. 5(2)(f): legitimate interest |
| Grant Agreement obligations | Keeping service records, KPI and performance reporting, preparation for checks and audits by European Union bodies | Art. 5(2)(f): legitimate interest; for checks and audits Art. 5(2)(e): establishment, exercise and protection of a right |
| EDIH network reporting | Reporting digital maturity assessment (DMA) results and the contact details of served organisations to the European Commission’s EDIH network platform, as required by the EDIH programme (Sections 5 and 6) | Art. 5(2)(f): legitimate interest |
| Communication and information | Responding to information requests, notifications regarding applications and services | Art. 5(2)(c); Art. 5(2)(f) |
| Event management | Registration, participant lists, name badges, event logistics | Art. 5(2)(c); Art. 5(2)(f) |
| Information security and system logs | Security of the website and systems, keeping access logs | Art. 5(2)(f): legitimate interest; data security obligation under KVKK Art. 12 |
| Handling of legal claims | Dispute management, legal defence, responding to requests of competent authorities | Art. 5(2)(ç); Art. 5(2)(e) |
| Electronic messages | Sending announcements of events, calls, services and news of DIGI4AGE (Boğaziçi University) by e-mail/SMS. Consortium partners’ own product and service promotions are not covered. | Explicit consent (Art. 5(1)), Consent Declaration item 1 |
| Ecosystem matchmaking | Sharing your contact details and your enterprise’s needs profile with investors, corporates and ecosystem actors established in Türkiye | Explicit consent (Art. 5(1)), Consent Declaration item 2 |
| Promotion and visibility | Use of your name, title and image in success stories, event news and Project promotional materials | Explicit consent (Art. 5(1)), Consent Declaration item 3 |
The ground shown as Art. 5(2)(c) applies to natural persons who are party to the contract (e.g. sole proprietors). Data of persons representing legal entities or named as contact persons are processed for the same purposes under Art. 5(2)(f) (legitimate interest).
Pursuant to Article 8 of KVKK, your personal data may be transferred to the following recipient groups, solely for the purposes stated below:
| Recipient group | Purpose of transfer | Legal ground |
|---|---|---|
| DIGI4AGE Consortium partners: Boğaziçi University Center for Targeted Therapy Technologies (BU-CT3, affiliated entity); Biyomod Biyomedikal Modül Çözümleri Bilişim Elektronik Sanayi ve Ticaret Ltd. Şti.; Türkiye Metal Sanayicileri Sendikası (MEXT); Radius Bilgisayar ve Yazılım Sanayi Ticaret Ltd. Şti.; Istanbul Health Industry Cluster Association (İSEK); Teknopark İstanbul A.Ş.; Istanbul Provincial Health Directorate | Delivery of the requested service by the relevant partner, coordination within the Consortium and service follow-up | Art. 5(2)(c); Art. 5(2)(f) |
| Third-party experts, trainers, mentors and test/laboratory service providers engaged for the performance of the service | Delivery of the requested service | Art. 5(2)(c); Art. 5(2)(f) |
| Competent public institutions, judicial and administrative authorities | Fulfilment of legal obligations, responding to lawful requests | Art. 5(2)(ç); Art. 5(2)(e) |
| European Commission Directorate-General for Communications Networks, Content and Technology (DG CONNECT) and the EDIH network support contractor (Digital Transformation Accelerator, DTA) | Reporting to the EDIH network platform: name and tax number of the served organisation; name, surname, position, business e-mail and business telephone of the contact person; DMA responses per organisation. The Commission processes these data under the EDIH Privacy Statement (https://european-digital-innovation-hubs.ec.europa.eu/edih-privacy-statement). | Art. 5(2)(f); subject to the conditions in Section 6 |
| European Health and Digital Executive Agency (HaDEA), the European Commission and audit bodies authorised under the Grant Agreement (European Anti-Fraud Office (OLAF), European Public Prosecutor’s Office (EPPO), European Court of Auditors and experts and audit firms acting on their behalf) | Project performance reporting (aggregated data). In case of checks and audits, access to Project records limited to what is necessary | Aggregated anonymised data are outside the scope of KVKK. Audit access: Art. 5(2)(e), subject to the conditions in Section 6 |
| Suppliers and data processors with which the University and the DIGI4AGE Consortium partners have a contractual relationship (IT, hosting/cloud, form and CRM infrastructure, event organisation, accounting and audit) | Operation of technical infrastructure, information security, event and financial processes | Art. 5(2)(f); under a data processing agreement |
| Legal advisers, judicial and enforcement authorities | Establishment, exercise and protection of rights | Art. 5(2)(e) |
| Investors (venture capital funds, crowdfunding platforms), corporates and ecosystem actors established in Türkiye, outside the Consortium | Creating matchmaking and collaboration opportunities | Explicit consent only (Consent Declaration item 2) |
For matchmaking opportunities with organisations abroad (e.g. other European Digital Innovation Hubs or investors established abroad), your personal data are not transferred; DIGI4AGE only makes an introduction and you establish contact yourself.
As a rule, your personal data are processed and stored in Türkiye. Transfers abroad under Article 9 of KVKK may occur in the following cases:
No personal data are transferred to organisations abroad for ecosystem matchmaking (Section 5). Transfers abroad will in no case be based solely on your explicit consent; explicit consent will be relied upon only in the occasional circumstances provided for in Article 9(6) of KVKK.
| Data / process | Retention period | Basis |
|---|---|---|
| Application, service and event records | For the duration of the Project and 5 years after the final payment under the Grant Agreement; if checks, audits or disputes are ongoing, until they end | Grant Agreement No. 101300776, Data Sheet point 6 and Art. 20.1 (record-keeping: 5 years after final payment) |
| Rejected or incomplete applications | For the duration of the Project and 5 years after the final payment under the Grant Agreement; if checks, audits or disputes are ongoing, until they end | Evidence of the assessment of applications in checks and audits under the Grant Agreement (Grant Agreement Art. 20.1 and Art. 25); Art. 5(2)(f) |
| System and access logs | 1 year | Information security requirement (KVKK Art. 12); Art. 5(2)(f) |
| Service agreements, undertakings and records relating to a specific risk of dispute | General limitation period (10 years) | Turkish Code of Obligations No. 6098, Art. 146 |
| Consent-based processing (message permission, matchmaking) | Until consent is withdrawn | KVKK Art. 5(1), Art. 7 |
| Promotion and visibility content (website, social media) | Until consent is withdrawn and at most 5 years after the end of the Project | KVKK Art. 5(1), Art. 7; Personal Data Protection Board Principle Decision No. 2026/1301 |
| Electronic message approval and opt-out records | 3 years from the end of the approval | Regulation on Commercial Communication and Commercial Electronic Messages, Art. 13(2) |
Upon expiry of these periods, your personal data are deleted, destroyed or anonymised during periodic destruction cycles in accordance with the Regulation on the Deletion, Destruction or Anonymisation of Personal Data and the University’s Personal Data Retention and Destruction Policy.
Pursuant to Article 11 of KVKK, you have the right, by applying to the University, to:
How to apply. In accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller, you may submit your application (i) in writing to “Boğaziçi University, 34342 Bebek / Istanbul”, (ii) to info@digi4age.com from the e-mail address you have previously notified to the University and that is registered in our system, (iii) to the KEP address bogaziciuniversitesi@hs01.kep.tr, (iv) with a secure electronic signature or mobile signature, or (v) by completing the Data Subject Application Form published on the University website and sending it through one of these channels. Applications must be made in Turkish and must include your name, surname, signature (for written applications), Turkish ID number or nationality/passport number, address for service, e-mail/telephone for notification, and the subject of your request.
Time limit and complaint. Your application will be concluded free of charge within thirty (30) days at the latest. If a written response exceeds ten pages, a fee of 1 Turkish lira may be charged for each additional page; if the response is given on a recording medium, a fee up to the cost of the medium may be charged (Communiqué on Application to the Data Controller, Art. 7). If your application is rejected, the response is found insufficient, or no response is given in time, you may lodge a complaint with the Personal Data Protection Board within thirty (30) days from the date you learn of the response and in any case within sixty (60) days from the date of application (KVKK Arts. 13 and 14).
This notice may be updated in line with changes in legislation or Project processes. The current text is published on this page.