Privacy Policy
Last updated: 13 August 2026
Work in Türkiye ("Work in Türkiye", "we", "us", "our") operates the website workintr.com and the mobile applications WorkinTR Staff (for candidates) and WorkinTR Partner (for partner agencies and case handlers). Together we call these the "Services".
This Privacy Policy explains what personal data we collect through the Services, why we collect it, the legal basis on which we process it, who we share it with, how long we keep it, how we protect it, and the rights you have over it. It applies to everyone who uses the Services: candidates looking for spa and wellness work in Türkiye, employers, and partner agencies.
If you do not agree with this policy, please do not use the Services. If you have any question about it, write to info@workintr.com.
1. Who is responsible for your data
Work in Türkiye is the controller of the personal data described in this policy. Under Turkish Personal Data Protection Law No. 6698 ("KVKK") we act as veri sorumlusu (data controller); where the EU/UK General Data Protection Regulation ("GDPR") applies to you, we act as controller within the meaning of that regulation.
Contact for all privacy matters, including the exercise of your rights: info@workintr.com.
2. The short version
- We collect the information you enter into your profile, the documents you upload, the messages you exchange with our team, and a small amount of technical data needed to run the apps.
- We use it for one purpose: to place you in a spa or wellness job in Türkiye and to run the work permit and employment process that follows.
- We never sell your personal data, and we never share it with advertisers or data brokers.
- Our apps contain no advertising SDKs, no analytics SDKs and no tracking identifiers. We do not collect your location.
- Health information, religion and criminal-record documents are processed only with your explicit consent.
- You can delete your account and your personal data from inside the app at any time.
3. What personal data we collect
3.1 Account information
First name, last name (optional — a single legal name is accepted), nickname, e-mail address, telephone number, password, preferred language, profile photo, referral code if you were introduced by a partner agency, account status, and the time of your last sign-in. Your password is stored only as a one-way cryptographic hash; we cannot read it, and no member of our staff can see it.
3.2 Candidate profile
To present you to employers and to prepare a work permit application, we collect: date and place of birth, gender, height and weight, marital status and spouse information, nationality, country of residence and the country you are applying from, passport type, passport number and its issue and expiry dates, education (level, school, department, city, country and duration of study), work experience and previous employers, profession and specialities, skills, certificates, spoken languages and your English and Turkish level, salary expectation and currency, availability and earliest start date, willingness to relocate, preferred cities in Türkiye, a short biography, home address and city, the type of application you are making, whether you already hold a Turkish work permit, and — where such a record exists — details of any previous deportation from Türkiye.
3.3 Special categories of personal data
Some of the information above is treated as sensitive under the KVKK and as a special category under the GDPR:
- Health data — whether you have a health condition, your health notes, and the content of any health report you upload.
- Religion — only where you choose to state it.
- Criminal record data — the police record certificate required by Turkish authorities for a work permit.
We process these only on the basis of your explicit consent, which you give when you register and when you upload the relevant document, and only because employers and the Turkish authorities require them before a foreign national can be employed. You can withdraw that consent at any time (see section 10).
3.4 Documents you upload
Depending on your process, these may include: passport, portrait photograph, full-body photograph, diploma, professional certificates, health report, police record certificate, work permit, residence permit, transfer permit, deportation documents, reference letters, CV, and the signed employment contract. Accepted formats are JPG, JPEG, PNG, WEBP, HEIC, HEIF and PDF, up to 12 MB per file.
Uploaded files are stored on private server storage. They are not published at a public web address and cannot be reached by anyone who is not signed in and authorised.
3.5 Messages and support
The conversations you have with our operations team through the app, their contents, and their timestamps.
3.6 Process and financial records
Placement records and their status history, work permit case files and stage history, payments and invoices, commission records, membership and subscription records, and any review you leave about a case handler.
3.7 Device and technical data
- Push notifications. If you allow notifications, we store the notification token issued to your device by Firebase Cloud Messaging, together with the platform (iOS or Android), the app version, the device name, your app language and the time the record was last used. A device token belongs to one account at a time: if someone else signs in on the same phone, the token moves to that account so that notifications never reach the wrong person.
- Consent and contract records. When you accept a contract or a consent text, we record which version you accepted, the date and time, your IP address and your browser or app user agent. This is kept as a legal audit trail and is what allows us to prove that consent was properly obtained.
- Server records. Our servers keep standard technical logs — IP address, request time, error records — for security, abuse prevention and troubleshooting.
3.8 Where the data comes from
Most of it comes from you. In addition: a partner agency may create a candidate profile and invite you by e-mail (you then set your own password and control the account); our operations staff add process notes and status records; and employers may give feedback on your application.
3.9 What we do not collect
This section is deliberately specific, because "we may collect various information" is not an honest disclosure:
- We do not use advertising identifiers (IDFA on iOS, Advertising ID on Android).
- We do not embed third-party analytics, attribution or advertising SDKs in our apps.
- We do not collect your location. The apps do not request any location permission.
- We do not access your contacts, calendar, SMS messages, call logs, microphone or the other apps installed on your device.
- We access the camera and photo library only at the moment you choose to attach a document, and only the file you select is uploaded.
- The website contains no third-party tracking scripts and sets no advertising cookies.
The permissions the apps request are limited to: internet access; notification permission (required from Android 13 onwards); and, on iOS, camera and photo library access at the point of document upload.
4. Why we use your data, and our legal basis
- Creating and operating your account — necessary for the performance of our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5/2-c).
- Matching you with employers and presenting your profile — performance of our contract with you, and your explicit consent for the disclosure of your profile to a specific employer.
- Preparing and following work permit, visa and residence applications — performance of our contract and compliance with our legal obligations (GDPR Art. 6(1)(b) and (c); KVKK Art. 5/2-ç).
- Communicating with you — e-mail notifications, push notifications and in-app messages about your process; performance of our contract and our legitimate interest in keeping you informed.
- Payments, invoicing, commissions and accounting — compliance with legal obligations under Turkish tax and commercial legislation.
- Health data, religion and criminal-record documents — your explicit consent (GDPR Art. 9(2)(a) and Art. 10; KVKK Art. 6).
- Transferring your data to Türkiye and disclosing it to employers and authorities — your explicit consent, given at registration (KVKK Art. 9; GDPR Art. 49(1)(a)).
- Security, abuse prevention and technical logs — our legitimate interest in keeping the Services safe (GDPR Art. 6(1)(f); KVKK Art. 5/2-f).
- Answering your data protection requests and keeping the audit trail — compliance with our legal obligations.
We do not make decisions about you by automated means alone that produce legal effects or similarly significantly affect you, and we do not profile you for advertising. Shortlisting and matching are always reviewed by a person.
5. Who we share your data with
- Prospective employers — spa, hotel and wellness businesses in Türkiye. Until a process actually starts, employers see a masked profile without your identifying details. Once you are put forward for a specific position, your full profile and the documents required for that position are disclosed.
- Partner agencies and case handlers — only in respect of the candidates they introduced or whose work permit file they are handling.
- Turkish public authorities — including the Ministry of Labour and Social Security, consulates, migration and law enforcement authorities and the tax administration, where a work permit, visa, residence or employment process requires it or where the law obliges us to disclose.
- Service providers acting on our instructions, under contract and confidentiality:
- our hosting provider in Türkiye, which operates the servers and backups;
- our e-mail service provider, which delivers transactional e-mails;
- Google (Firebase Cloud Messaging), which delivers push notifications. It receives only the device token and the notification content — never your profile or your documents.
- Professional advisers — lawyers, accountants and auditors, under a duty of confidentiality.
- Courts and authorities, where we are legally required to disclose, or to establish, exercise or defend legal claims.
We do not sell, rent or trade personal data. We do not share it with advertisers, ad networks or data brokers.
6. International transfers
Our servers are located in Türkiye. If you apply from outside Türkiye — as most of our candidates do — your personal data is transferred to Türkiye and processed there. You give your explicit consent to this transfer when you register, in line with Article 9 of the KVKK.
If you are in the European Economic Area or the United Kingdom: Türkiye is not currently covered by an adequacy decision. Transfers of your data to Türkiye are therefore based on your explicit consent under Article 49(1)(a) of the GDPR, after you have been informed of the possible risks of a transfer without an adequacy decision or appropriate safeguards. You can withdraw this consent at any time, though we will then no longer be able to continue your placement process.
Push notification tokens are processed by Google through its global Firebase infrastructure.
7. How long we keep your data
- Account and profile data — for as long as your account exists.
- Uploaded documents — for the duration of your placement and work permit process; deleted when you delete your account.
- Messages — deleted when you delete your account.
- Push notification tokens — until you turn notifications off, sign out, or delete your account.
- Technical server logs — kept for a limited period for security purposes and then overwritten.
- Records we are required by law to keep — payment lines, work permit files, placement records and the contract acceptance audit trail are retained in a form that no longer identifies you, for the statutory retention periods under Turkish law (up to ten years for commercial books and records under the Turkish Commercial Code), and are destroyed at the end of those periods.
8. How we protect your data
- All traffic between your device and our servers is encrypted with HTTPS/TLS.
- Passwords are stored as salted bcrypt hashes and are never stored or transmitted in readable form.
- Your passport number and your health notes are additionally encrypted in the database, so that they are unreadable even to someone with direct database access.
- Uploaded documents are held on private storage, outside the public web root, and are served only to authorised users.
- Access is role-based: each member of staff sees only what their role requires, and your identity is masked from employers until a process starts.
- The mobile apps store your session token in the device's secure storage (Keychain on iOS, EncryptedSharedPreferences on Android).
- Deleting your account immediately invalidates every session token issued to it, on every device.
No system can be completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify you and the Turkish Personal Data Protection Authority (and, where applicable, your supervisory authority) within the periods the law requires.
9. Children
The Services are employment services intended for adults. You must be at least 18 years old to create an account. We do not knowingly collect personal data from children. If you believe a person under 18 has provided us with personal data, write to info@workintr.com and we will delete it.
10. Your rights
Under Article 11 of the KVKK, and under Articles 15 to 22 of the GDPR where it applies to you, you have the right to:
- learn whether we process your personal data, and request information about that processing;
- obtain a copy of the personal data we hold about you;
- have inaccurate or incomplete data corrected;
- have your data erased or destroyed;
- receive your data in a structured, machine-readable format and have it transmitted to another controller (data portability);
- object to processing, or ask us to restrict it;
- withdraw any consent you have given, at any time — withdrawal does not affect the lawfulness of processing carried out before it;
- request that any correction, erasure or restriction be notified to the third parties to whom your data was disclosed;
- object to a decision made solely by automated processing, and to claim compensation for damage suffered as a result of unlawful processing;
- lodge a complaint with the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) or, if you are in the EEA or the UK, with your local supervisory authority.
How to exercise them. In the WorkinTR Staff app, open More → Data requests and submit your request, or send it by e-mail from your registered address to info@workintr.com. We will verify that the request comes from you and respond within 30 days at the latest, free of charge, as required by Article 13 of the KVKK.
11. Deleting your account
You can delete your account and the personal data attached to it at any time:
- From inside the app — More → Settings → Delete my account, confirmed with your password.
- By e-mail — if the app is no longer installed, write to info@workintr.com from your registered address with the subject "Account deletion". We verify that the request comes from the account owner and then follow the same process.
What happens when you request deletion. Your account is closed straight away: every session on every device is ended, sign-in is blocked, and your push notification device records are removed. Nothing further is required from you. Your personal data is then permanently erased after a waiting period of 30 days.
You can change your mind during those 30 days. Cancel either through the link in the confirmation e-mail we send you, or by signing in with your e-mail address and password and choosing "Cancel my deletion request". Once the 30 days have passed, the erasure runs automatically and cannot be undone.
The erasure removes your name, contact details, full candidate profile, all uploaded documents including the files themselves, all conversations and message contents, all notifications, all sign-in tokens and all push notification device records. The account can no longer be signed in to; you may register again later with the same e-mail address, but none of the previous data returns. The records described in section 7 are retained in a form that no longer identifies you.
The full detail is on our Delete Your Account page.
12. Cookies
The workintr.com website uses strictly necessary cookies only: a session cookie, which keeps you signed in and holds your language preference, and a security cookie (XSRF token) that protects forms against cross-site request forgery. We set no advertising cookies and embed no third-party tracking scripts. The WorkinTR Staff and WorkinTR Partner mobile apps do not use cookies at all. See our Cookie Policy.
13. Push notifications
If you allow them, we send push notifications about your process: document requests, status changes in your placement or work permit file, and new messages from our team. You can turn them off at any time in your device settings, or by signing out of the app — in either case the device record is removed. Turning them off may mean you miss a time-sensitive step in your process.
14. Links to other sites
The Services may link to websites we do not operate. This policy does not apply to them, and we are not responsible for their privacy practices. Please read their own policies.
15. Changes to this policy
We may update this policy as the Services or the law change. The date at the top of the page always shows the current version. If we make a material change, we will tell you in the app or by e-mail before it takes effect. Continuing to use the Services after a change means you accept the updated policy.
16. Contact us
Work in Türkiye
E-mail: info@workintr.com
Related documents: Data Protection Notice (KVKK) · Cookie Policy · Terms of Use · Delete Your Account