Teknik Danışman Teknik Danışman
Pricing Developers Integrations Changelog Status
TR Log in Start free

Privacy Policy & KVKK/GDPR Noteice

Data controller information notice under Turkish PDPL (Law No. 6698, Art. 10) and GDPR.

Son güncelleme: 2026-06-21

1. Data Controller

This notice is prepared under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR") by Ali Enis Tekin ("Data Controller"), operator of the Teknik Danışman platform, regarding the processing of personal data of panel users.

Data ControllerAli Enis Tekin
Contactlegal@teknikdanisman.net
KVKK Contact Personkvkk@teknikdanisman.net
VERBIS Registration NoRegistration application in progress — this section will be updated once the registration number is issued.

2. Categories of Personal Data Processed

The following categories of data may be processed in the course of providing our service:

CategoryData TypeSource
IdentityName, surname, username, Turkish ID no. (only if the employer uploads it for HR documents)User / Employer
ContactEmail address, phone, addressUser / Employer
EmployeePosition, department, start/end date, leave/warning recordsEmployer
Transaction securityIP address, session data, browser/device info, MFA status, audit logAutomatically collected
FinancialBilling address, payment method reference (card number stored by the payment provider, not by us)User
Visual/audioProfile picture, company logoUser / Employer

3. Purpose and Legal Basis of Processing

PurposeLegal Basis (KVKK Art. 5/2)
Performance of the service agreement, creating and maintaining the user accountFormation or performance of a contract (c)
Billing, payment tracking, commercial and technical supportLegal obligation (a) / Performance of contract (c)
Security audit, fraud prevention, brute-force protection, audit loggingLegitimate interest of the controller (f)
Marketing communication (only with explicit consent)Explicit consent (a) — Law No. 6563
Providing tools to the customer (employer) for running HR/IT operationsPerformance of contract (c) — we act as Data Processor for the employer
Fulfilment of legal obligations (tax, commercial, KVKK, GDPR)Legal obligation (a)
Data Controller / Data Processor Rolee For employee data stored in the customer (employer) panel, we act as Data Processor and the customer acts as Data Controller. This relationship is governed by the Data Processing Agreement (DPA).

4. Data Transfers

Your personal data may be shared with the following third parties, only to the extent necessary to provide the service:

Recipient CategoryData TypePurposeLocation
Server infrastructure (Hetzner)All panel dataHostingGermany (EU)
Email provider (Microsoft 365 / Google Workspace — provider the customer connects via OAuth)Noteification email contentAutomated notification deliveryEU / US
Payment provider (iyzico)Billing infoCollectionTürkiye
AI service provider (Groq)Only user prompts entered in AI chat windowsResponse generationUS — provider commits to not storing data
Communication/support toolsContact info + support message contentCustomer supportEU / US

Cross-border transfers are made under appropriate safeguards (Standard Contractual Clauses / SCC) per KVKK Art. 9.

5. Retention Periods

Data CategoryRetention
Active user account dataFor the duration the account is active
Passive/deleted account dataPermanent deletion 60 days after account deletion
Audit log records6 months (for security investigation needs)
Invoice and commercial records5 years under Turkish Tax Procedure Law Art. 253, 10 years under the Turkish Commercial Code
Labour Law records (uploaded by the customer)10 years per Labour Law Art. 32 (customer's responsibility)

6. Data Subject Rights (KVKK Art. 11 / GDPR Art. 15-22)

As a data subject you have the following rights:

  • To learn whether your personal data is processed
  • To request information about processing, if any
  • To learn whether the data is used for its intended purpose
  • To know the third parties to whom the data was transferred domestically or abroad
  • To request correction if incomplete/incorrect
  • To request deletion/destruction under the conditions in KVKK Art. 7
  • To object to automated system analyses that produce adverse results
  • To claim damages if you have been harmed by unlawful processing
  • (GDPR) Data portability — to download your data in a machine-readable format

You can submit requests in writing to kvkk@teknikdanisman.net or via the methods prescribed by KVKK. We respond free of charge within 30 days.

7. Cookie Usage

The panel only uses the following strictly necessary cookies — no marketing or analytics cookies:

  • PHPSESSID — Session management (HttpOnly, Secure, SameSite=Lax)
  • td_remember — "Remember Me" feature (HttpOnly, opt-in)
  • td_trusted_* — 2FA trusted device recognition

All cookies are retained for the duration of your session or up to 30 days; they are not shared with third parties.

8. Security Measures

For a detailed security architecture see the Trust Center. Short summary:

  • Passwords are bcrypt-hashed, never stored in plain text
  • Sensitive fields are encrypted with AES-256-CBC
  • All connections use HTTPS + HSTS
  • 2FA (TOTP) is mandatory for administrator accounts
  • Brute-force protection, audit logging, multi-tenant DB isolation
  • Regular backups with a target RPO ≤ 1 hour, RTO ≤ 4 hours

9. Data Breach Noteification

Under KVKK Art. 12/5 and GDPR Art. 33-34, in the event a data breach is detected:

  • The Turkish Personal Data Protection Authority is notified within 72 hours
  • Affected data subjects are notified without delay
  • The nature and scope of the breach, measures taken, and contact information are shared

10. Changes

This notice may be updated in line with changes in legislation and the scope of our service. The current version is always published on this page; active users are notified by email for material changes.

11. Complaints and Applications

If you are not satisfied with our response, you have the right to lodge a complaint with the Turkish Personal Data Protection Authority:

www.kvkk.gov.tr · Nasuh Akar Mah. Ziyabey Cad. 1407. Sok. No:4 Balgat-Çankaya/ANKARA

Teknik Danışman Teknik Danışman

SMB operations across 5 corridors. Built in Türkiye, hosted in Türkiye.

teknikdanisman.com.tr · teknikdanisman.net
admin@teknikdanisman.com.tr
admin@teknikdanisman.net

Product

  • Pricing
  • Integrations
  • Self-host
  • Changelog
  • Roadmap

Developers

  • API
  • Authentication
  • Examples
  • Webhooks
  • Postman

Company

  • About
  • Contact
  • Status
  • Incident History

Trust

  • Trust Center
  • Privacy
  • DPA
  • security.txt
© 2026 Teknik Danışman — Ali Enis Tekin. All rights reserved.
All systems operational