Usage discovery
We establish which AI services people really rely on, using sign-in records, browser and firewall data and a brief anonymous questionnaire, so you see the facts without anyone being blamed.
Generative AI did not wait for a purchasing decision. Across Turkish SMEs, employees already paste quotations, customer correspondence and even contract drafts into free chatbots under private accounts. Picture an architecture practice where one designer condenses a tender specification with a free assistant, a colleague uploads the client list to a different service to have it grouped, and the managing partner knows about neither. With consumer tiers, it is often unclear whether prompts help train the model, in which country they are stored and how long they are kept. Prohibition is no answer, because it only pushes the habit out of sight. Turkey currently has no dedicated AI statute, yet KVKK still governs any personal data involved, and the Authority has issued recommendations on generative AI. Businesses that sell into the EU should also keep the EU AI Act in view. What we want is productive AI use in which client files and internal figures stay under your control. That takes an approved tool, a single page of rules and around half an hour of training per person.
Nobody wants to stand in the way of useful AI. The task is to keep client and company information inside boundaries you have chosen.
We establish which AI services people really rely on, using sign-in records, browser and firewall data and a brief anonymous questionnaire, so you see the facts without anyone being blamed.
Candidates typically include Microsoft 365 Copilot, the free Copilot Chat signed in with a work identity and the business tiers of ChatGPT or Gemini. We weigh contract terms, where data is held, whether prompts feed training and the cost, then recommend one.
Copilot surfaces anything the signed-in person is allowed to open. Payroll spreadsheets or board minutes shared with the whole organisation must be locked down before it goes live.
One short document listing the sanctioned tools, the information that stays out of prompts (personal data, confidential client material, credentials), how answers are double-checked and who to contact with questions.
Unsanctioned AI sites are blocked or display a caution banner, and DLP rules stop confidential text from being pasted into chat windows.
A compact video course covering good practice, common pitfalls and data protection; attendance is logged. If you sell into the EU, that log also helps demonstrate the AI literacy the EU AI Act expects.
A matter of weeks takes you from improvised, individual use to an organised set-up the team genuinely likes.
An overview of the services people use and the jobs where AI really saves time: drafting quotes, answering emails, condensing documents, translating.
Selection of a primary tool, two at most, a review of its contract and data processing terms, and a briefing pack for your lawyer's KVKK assessment.
Licences assigned, the tool configured, guard rails and rules in place, then every employee completes the training.
Once people have worked with it for a while, we review real usage, refine the rules and add further use cases.
Forbidding AI does not stop it; it only hides it. People seldom abandon something that saves them an hour a day, so a ban simply moves the work onto personal phones. A good sanctioned tool plus clear rules lowers the risk and lets the team get genuine value from AI.
Not at the moment. KVKK applies wherever personal data is processed, and the Authority has published recommendations on generative AI and personal data. Selling goods or services into the EU may bring the EU AI Act into play as well. Please ask your legal adviser for a formal legal view.
Under the provider's business terms your inputs are excluded from model training, and you gain an admin console, user management and usually retention controls. Free and personal accounts either lack those protections or leave them to each individual's settings, which matters most when client data is involved.
Permission hygiene comes first. Copilot will find and summarise anything a user can already open, so a salary file accidentally shared with the whole company could appear in reply to a single question. Review SharePoint and OneDrive sharing, introduce sensitivity labels and roll out to a small group first.
No, reading individual prompts is not the aim. Guard rails block specific content, such as ID numbers or documents labelled confidential, from reaching unsanctioned services. Who can view which events is agreed in advance, and we recommend telling staff how it works.
Describe the AI tools in use today and whether you are on Microsoft 365 or Google Workspace. We will recommend where to begin.
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.