İçeriğe geç

Privacy Policy

Last updated: October 6, 2026

1. Data controller

The data controller with respect to your personal data is Atlantic Formations LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA. Contact: [email protected]. This policy has been prepared with regard to the EU General Data Protection Regulation (GDPR), Türkiye's Personal Data Protection Law No. 6698 (KVKK), the UK GDPR and Data Protection Act 2018, and applicable U.S. state privacy laws.

2. What data do we collect?

  • Account data: full name, email, phone number, password (stored as an irreversible hash).
  • Application data: the name of the company to be formed, the founder's full name, country, contact details, and application notes.
  • Identity verification and compliance data: passport or ID card image, proof of address, where needed a photo taken with the ID, and the result of sanctions list screening (for identity verification and legal compliance obligations).
  • Payment data: payments are processed by licensed payment institutions through the secure payment link we send you; your card number never reaches our servers. We receive only the transaction amount, date, and status.
  • Technical data: IP address, browser type, pages visited, and cookies (see the Cookie Policy).
  • Correspondence: support requests, email, and WhatsApp messages.
  • Mail data: if you use an address and mail service, scanned images of letters addressed to your company.

3. Purposes and legal bases of processing

PurposeLegal basis (GDPR / KVKK)
Performance of company formation and related servicesFormation and performance of a contract
Account creation, verification, and securityPerformance of a contract; legitimate interest
Legal obligations (KYC, anti-money-laundering, tax and commercial law)Compliance with a legal obligation
Support and communicationPerformance of a contract; legitimate interest
Service announcements and marketing emailsExplicit consent (withdrawable at any time)
Site security and fraud preventionLegitimate interest

4. Who do we share data with?

Your data is never sold. It is shared only to the extent necessary to perform the service, with the following parties:

  • Government agencies: the Wyoming Secretary of State, the IRS, Companies House and HMRC in the UK, and other relevant authorities (for formation and compliance filings).
  • U.S. registered agent partner (Registered Agents Inc.): to provide the registered agent service and to receive and forward official notices to you.
  • Identity verification provider (Stripe Identity — Stripe, Inc.): to collect your documents through a secure link and verify them.
  • UK partner: for UK formations, our partner xxx, an authorised agent registered with Companies House, for filings, identity verification, the registered office address, and mail handling. Our partner also retains identity records itself as required by anti-money laundering law.
  • Service providers: licensed payment institutions (payments), Resend (email delivery), Vercel (hosting), Upstash (database) — each under its own data processing agreement.
  • Professional partners: accounting/tax partners upon your request, and only with your approval.
  • Legal requirement: pursuant to a court order or a request from a competent authority.

4.1 The Companies House public register

When you form a UK company, the law requires the names, nationality, country of residence, occupation, month and year of birth, and service address of directors and PSCs to be published on the Companies House register, where they are publicly and permanently available. Your home address and full date of birth are not published. Publication is a statutory function of Companies House and cannot be removed by us.

5. International transfers

Our servers and service providers are located primarily in the United States; for UK services, data is transferred to our partner in the United Kingdom and to Companies House. Transfers from the EU and Türkiye rely on appropriate safeguards such as your explicit consent, necessity for the performance of the contract, and/or Standard Contractual Clauses (SCCs).

6. Retention periods

  • Account data: for as long as your account is active, and for a reasonable period after closure.
  • Company formation records and invoices: for the minimum periods required by tax and commercial law (generally 5–10 years).
  • Identity verification and compliance records: 5 years after the service relationship ends (anti-money-laundering and sanctions compliance obligations); securely deleted thereafter.
  • Marketing permissions: until you withdraw your consent.

7. Your rights

Under GDPR Articles 15–22 and KVKK Article 11, you have the right to:

  • Access your data and learn whether it is being processed,
  • Request rectification, erasure, or restriction of processing,
  • Object to processing and request data portability,
  • Withdraw your consent at any time,
  • Lodge a complaint with a supervisory authority (your local data protection authority in the EU; the KVKK Authority in Türkiye; the Information Commissioner's Office (ICO) in the UK).

You can submit requests to [email protected]; we respond within 30 days at the latest after verifying your identity.

8. Security

Your data is encrypted in transit using TLS. Passwords are stored using irreversible algorithms. Access is restricted to personnel who need it to perform their duties. We remind you that no system can be 100% secure and recommend using a strong, unique password for your account. In the event of a data breach, we act in accordance with our legal notification obligations.

9. Children

Our services are not directed at persons under 18, and we do not knowingly collect data from children.

10. Changes

Updates to this policy are announced on the site; for material changes, you will also be notified by email.