Privacy Policy
This Privacy Policy explains how pmgix (“we”, “us”, or “our”) processes personal data when you visit our website, contact us, request advisory services, subscribe to updates, or otherwise interact with us. We are committed to handling personal information responsibly and in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Turkish Personal Data Protection Law (KVKK), and other applicable privacy legislation.
This policy should be read together with our Cookie Policy and Terms of Use.
1. Who is responsible for your data
pmgix acts as the data controller for personal data processed through this website and in connection with our advisory, training, and business development activities, unless we inform you otherwise in a specific engagement letter or contract.
pmgixSarphan Finans Park, Finans Street No. 5, Financial Center
Ümraniye, Istanbul 34760, Türkiye
Email: privacy@pmgix.com
General enquiries: info@pmgix.com
2. Personal data we collect
Depending on how you interact with us, we may collect the following categories of information:
- Identity and contact details — name, job title, organisation, email address, telephone number, and postal address.
- Professional information — sector, project type, transaction background, and other details you provide in enquiries, RFP submissions, or advisory discussions.
- Communications — messages, meeting notes, correspondence, and feedback you send to us.
- Website and technical data — IP address, browser type, device identifiers, pages viewed, referral source, and cookie preferences. See our Cookie Policy for more detail.
- Marketing preferences — your choices regarding newsletters, event invitations, and similar communications.
- Recruitment data — CVs, employment history, and application materials if you apply for a role with pmgix.
We do not intentionally collect special categories of personal data (such as health information or biometric data) through this website. Please avoid submitting sensitive information unless we specifically request it and explain the lawful basis for doing so.
3. How and why we use personal data
We use personal data for legitimate business purposes, including to:
- respond to contact requests, RFPs, and other enquiries;
- provide, administer, and improve our advisory, training, and related professional services;
- manage client relationships, proposals, and contractual obligations;
- send relevant insights, invitations, and service updates where permitted;
- operate, secure, and analyse use of our website;
- comply with legal, regulatory, and professional obligations;
- protect our rights, prevent fraud, and maintain business records;
- process job applications and manage recruitment activities.
4. Legal bases for processing
Where GDPR or UK GDPR applies, we rely on one or more of the following legal bases:
| Processing activity | Typical legal basis |
|---|---|
| Responding to enquiries and delivering contracted services | Performance of a contract or steps prior to entering a contract |
| Website operation, security, and essential cookies | Legitimate interests and, where required, consent |
| Marketing communications to business contacts | Legitimate interests or consent, depending on context and jurisdiction |
| Regulatory compliance and record-keeping | Legal obligation and legitimate interests |
| Recruitment and talent management | Legitimate interests, contract, and consent where applicable |
Where we process personal data under KVKK or other national laws, we do so in line with the conditions set out in those frameworks, including explicit consent, contractual necessity, or statutory authorisation where relevant.
6. International data transfers
pmgix operates internationally. Personal data may be transferred to, stored in, or accessed from countries outside your jurisdiction, including Türkiye, the European Economic Area (EEA), the United Kingdom, and other locations where we or our service providers maintain operations.
Where GDPR or UK GDPR requires safeguards for cross-border transfers, we implement appropriate measures such as Standard Contractual Clauses, adequacy decisions, or other mechanisms recognised by applicable law. You may request further information about transfer safeguards by contacting us at privacy@pmgix.com.
7. How long we keep data
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, including to satisfy legal, accounting, dispute-resolution, and professional record requirements. Retention periods vary depending on the type of data and our relationship with you.
Indicative retention practices include:
- enquiry and marketing records — typically up to three years after last meaningful contact, unless a longer period is justified;
- client and project files — for the duration of the engagement and thereafter as required by law or professional standards;
- website logs and analytics — generally for a limited operational period consistent with security and performance needs;
- recruitment applications — usually up to 24 months unless you consent to a longer retention for future opportunities.
8. Your privacy rights
Depending on your location, you may have rights to access, rectify, erase, restrict, or object to certain processing of your personal data, to data portability, and to withdraw consent where processing is consent-based. You also have the right to lodge a complaint with a supervisory authority.
Under GDPR and UK GDPR, these rights may include:
- the right to obtain confirmation as to whether we process your personal data;
- the right to receive a copy of your personal data in a structured, commonly used format where applicable;
- the right to request correction of inaccurate or incomplete information;
- the right to request deletion in certain circumstances;
- the right to object to processing based on legitimate interests or for direct marketing;
- the right to restrict processing in limited situations;
- the right to withdraw consent at any time, without affecting prior lawful processing.
To exercise your rights, email privacy@pmgix.com. We may need to verify your identity before responding. We aim to reply within one month, subject to applicable extensions for complex requests.
For a focused summary of how to submit a rights request, see our Data Protection Rights page.
9. Security measures
We apply administrative, technical, and organisational safeguards designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. Measures may include access controls, encryption where appropriate, secure hosting environments, staff training, and incident response procedures.
No method of transmission or storage is completely secure. If you believe your interaction with us is no longer secure, please notify us promptly.
10. Automated decision-making
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals. If this position changes, we will update this policy and provide any information required by law.
11. Children’s privacy
Our website and services are directed at business and professional audiences. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. The “Last updated” date at the top of this page indicates when the policy was most recently revised. Material changes will be highlighted on our website where appropriate.
13. Contact and complaints
For privacy questions, rights requests, or concerns about our data practices, contact: privacy@pmgix.com.
You may also raise a complaint with a relevant supervisory authority, including:
- Türkiye — Personal Data Protection Authority (KVKK): www.kvkk.gov.tr
- EEA — the data protection authority in your country of residence or workplace
- United Kingdom — Information Commissioner’s Office (ICO): ico.org.uk