Net Zero (netzero.com.tr) is operated by Climateware Teknoloji A.Ş. ("Climateware", "we"). References to "we" include Climateware and its corporate affiliates within the Peerless Ventures group. Climateware is the controller of personal data processed on Net Zero, under the Turkish Personal Data Protection Law No. 6698 (KVKK) and, where it applies, the EU General Data Protection Regulation (GDPR).

1. What information we collect

  • Account and profile data: email address, name, company or organisation, role, country, time zone and language preference. If you choose LinkedIn, we also process the LinkedIn provider identifier, verified-email status, profile name, profile image and locale returned by the provider.
  • Preferences and account actions: topics, sectors and funders you follow; saved items, collections, regulation follows, reminders and notification settings.
  • Communication and permission records: briefing, alert and marketing choices; consent and preference changes; verification, unsubscribe, suppression and delivery outcomes. These records apply and evidence your choices.
  • Requests you submit: contact details, choices, answers and request context from briefing-pack, solution-interest, specialist and applicability-tool forms.
  • Consented first-party measurement: only after analytics consent, session-scoped events such as page views, content impressions, opens, reads, shares, outbound actions, canonical path, locale, campaign and referrer domain. The server one-way hashes the session identifier; analytics events do not include device, browser, precise location or a cross-session person identifier.
  • Security and operations logs: technical records such as request time, requested route, IP address and user agent may be processed to protect the service, diagnose faults and prevent abuse. They are separate from analytics events.
  • Cookies: see the Cookie policy for details.

2. How we use it

  • Providing, authenticating and managing the service; applying your follows, saved items, collections, reminders and notification choices.
  • Sending requested email briefings and alerts. Commercial email to recipients in Türkiye is sent only when Law No. 6563 and applicable İleti Yönetim Sistemi (İYS) requirements are satisfied; withdrawal is available in each message and in Account.
  • Evaluating and improving the product through first-party session measurement, only with analytics consent.
  • Marketing of Climateware and Semtrio products and services — only with your consent.
  • Security, fault diagnosis and abuse prevention.
  • Compliance with legal obligations.

Legal bases under the GDPR

  • Performance of a contract — providing the service and managing your account.
  • Consent — email briefings and alerts, marketing of group products and services, first-party analytics and non-essential browser storage; you can withdraw consent at any time.
  • Legitimate interests — security, fault diagnosis and abuse prevention, where not overridden by your rights and freedoms.
  • Legal obligation — records and disclosures the law requires.

Legal bases under KVKK

Processing relies on the bases in KVKK Art. 5: establishment or performance of a contract (Art. 5/2-c), compliance with a legal obligation (Art. 5/2-ç) and legitimate interest (Art. 5/2-f). First-party analytics, marketing communications and the sharing of your data within the Peerless Ventures group for marketing purposes rely solely on your explicit consent (açık rıza) (Art. 5/1). Commercial-email choices are managed together with applicable İYS requirements.

3. How we disclose it

  • Peerless Ventures group companies — including Semtrio and Climateware affiliates — where needed for operational support; sharing for marketing happens only with your consent, and a one-time specialist handoff happens only when you explicitly request it.
  • Service providers — processors needed for hosting, databases, security and email delivery. LinkedIn supplies identity data only if you choose LinkedIn sign-in; when external email is enabled, Amazon Web Services (Amazon SES) processes recipient and delivery data. No third-party analytics, advertising or social-media tracker is active on Net Zero today.
  • A specialist recipient you explicitly choose — only for the stated one-time request and fields shown on that form. B2B feed customers receive published content only, not personal data.
  • Legal authorities — when required by law.
  • Business transfers — in a merger, acquisition or restructuring, subject to the protections in this policy.

4. Storage & security

We protect personal data with appropriate technical and organisational measures, including encryption in transit, access controls and least-privilege access. No method of transmission or storage is completely secure; where the law requires it, breaches are notified to you and to the competent authorities.

5. Retention

We retain data only for as long as the stated purpose, security, dispute resolution, proof of permission choices and legal duties require. Account data and account content remain while the account is active. Erasure requests are assessed against records that may need to remain to evidence communication choices or meet legal duties; an account is not erased until the applicable retention or anonymisation path is resolved. When erasure can proceed, direct account identifiers are removed and measurement events are de-linked from the account. Marketing use stops when you withdraw consent; withdrawal and suppression evidence remains only as long as needed to prevent further messages and demonstrate compliance. Consented measurement events remain pseudonymous only while needed for product trend analysis, then are deleted or de-identified. Cookie and browser-storage durations are listed in the Cookie policy.

6. Your rights & choices

Under KVKK Art. 11 you have the right:

  • To learn whether your personal data is processed,
  • To request information about the processing,
  • To learn the purpose and whether data is used in line with it,
  • To know the third parties to whom data is transferred, in Türkiye or abroad,
  • To request correction of incomplete or inaccurate data,
  • To request deletion or destruction of data under KVKK Art. 7,
  • To request that corrections and deletions be notified to recipients of the data,
  • To object to a result arising against you from analysis performed exclusively by automated systems,
  • To claim compensation for damage caused by unlawful processing.

Where the GDPR applies, you additionally have the rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability and objection, the right to withdraw consent at any time, and the right to lodge a complaint with a supervisory authority.

You can opt out of marketing email via the link in any message or in your account settings, and change your cookie choices at any time via the "Cookie preferences" link in the footer. Send requests to [email protected]; we answer within the periods set by KVKK and the GDPR.

7. International transfers

If a service provider processes personal data outside Türkiye or the EEA, the transfer follows KVKK Art. 9 and, where applicable, GDPR Chapter V. Climateware uses the safeguard applicable to that transfer, which may include an adequacy decision, standard contractual clauses and supplementary technical or organisational measures. You may request current provider and transfer-safeguard details from our contact address.

8. Changes & contact

This policy will be updated as the service evolves; material changes will be announced on this page. Questions and requests: Climateware Teknoloji A.Ş., BUDOTEK Teknopark, No: 8/29, 34775 Ümraniye, İstanbul, Türkiye · [email protected] · +90 216 807 06 33.