TapfleetLegal
Sign in
← All documents
Template — review with counsel before publishing

KVKK Privacy Notice (English translation)

Last updated: [date]

This is a faithful English translation of kvkk-aydinlatma-metni.md, provided for convenience. The Turkish text is the operative version; if the two differ, the Turkish governs.

This notice is prepared under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (the "Law") and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform, for people who use the Tapfleet service.

1. Identity of the data controller

Data controller: [Company Legal Name] Address: [Company Address] Country of incorporation: [Country of Incorporation] Contact: [Contact Email] Data protection contact: [Data Protection Contact] Contact person (irtibat kişisi, where VERBİS registration applies): [İrtibat Kişisi]

For personal data that appears inside a customer's own test data, app builds, screenshots or recordings, the customer organisation is itself the data controller (veri sorumlusu) and [Company Legal Name] acts as a data processor (veri işleyen); that relationship is governed by the Data Processing Agreement.

2. Personal data processed

  • Identity and contact data: name, email address.
  • Account and authorisation data: password hash, two-factor authentication records and backup codes, single sign-on identity, organisation membership and role (owner, admin, member, viewer), invitations.
  • Transaction security data: IP address, browser information, server and security logs, audit records (who did what and when).
  • Usage data: projects, tests, runs, device minutes metered per run, issues opened.
  • Financial data: subscription plan, spend limit, invoice details, and the customer identifier held at our payment service provider. We neither see nor store full card numbers.
  • Request and support data: what you send us through support channels.

No data is processed for advertising or profiling.

3. Purposes of processing

  • Formation and performance of the service contract; creating and managing the account and organisation membership.
  • Providing the service: executing test runs, storing the resulting artifacts and making them available.
  • Pricing, metering device minutes, invoicing and collection.
  • Information security: authentication, authorisation, prevention of abuse and fraud, maintaining isolation between organisations, keeping the audit log.
  • Monitoring and improving the continuity, performance and reliability of the service.
  • Handling requests and complaints and providing support.
  • Meeting legal obligations and pursuing legal claims.

4. Legal grounds

Your personal data is processed on the following grounds in Article 5(2) of the Law, without requiring your explicit consent:

  • Art. 5(2)(c) — directly related to the formation or performance of a contract: opening the account, providing the service, pricing and support.
  • Art. 5(2)(ç) — necessary for the data controller to fulfil a legal obligation: retention of invoice and accounting records, responding to requests from authorised public bodies.
  • Art. 5(2)(e) — necessary for the establishment, exercise or protection of a right: keeping audit records and using them as evidence in disputes.
  • Art. 5(2)(f) — necessary for the legitimate interests of the data controller, provided this does not harm your fundamental rights and freedoms: information security, prevention of abuse, and improvement of the service.

Processing that does not rest on any of the above — for example sending marketing electronic messages — is carried out only on your explicit consent, which you may withdraw at any time.

5. Transfers of personal data

Domestic transfers. Your personal data may be transferred, under Article 8 of the Law, to public institutions authorised to request it and to our legal and financial advisers, for the purpose of meeting legal obligations and pursuing legal claims.

Transfers abroad. The service's servers are located within the European Union: the control plane, database and object storage run at Hetzner (Falkenstein, Germany) and the iOS device pool at MacStadium (Dublin, Ireland). Cross-region replication is off. Your personal data is therefore transferred abroad within the meaning of Article 9 of the Law.

Legal basis for the transfer: [Cross-border transfer basis — the standard contract published by the Board will be signed and notified to the Board; to be completed by the customer's legal counsel]. The standard contract is notified to the Personal Data Protection Authority within the statutory period following signature.

Separately, providers you connect by your own choice (the AI model provider you use with your own key, an endpoint you operate yourself, Slack, PagerDuty, Jira, GitLab, BrowserStack) receive data on your instruction; your relationship with those providers is governed by your own contracts.

For the current list of recipients, see Subprocessors.

6. Method of collection

Your personal data is collected electronically, by partly automated and automated means:

  • directly from you, when you create an account, join an organisation, or enter information in the panel;
  • from your organisation, through invitations and role assignments made by its administrators, and through automated user provisioning records from your organisation's identity provider (SCIM/SSO);
  • automatically, through server logs, audit records and usage metering while you use the service;
  • through support channels, from the messages you send us.

7. Retention periods

Account and organisation records are kept while your account is open and for [period] after it ends; where legislation requires a longer period (for example invoice and accounting records), that period applies. Default retention for data generated inside the service: artifacts (screenshots) 30 days, logs and hierarchy dumps 30 days, video 14 days, run and test data 400 days, audit records 400 days, database backups 30 days. Organisation administrators may shorten these under Organization › Data & retention; no window exceeds 730 days. Data past its window is deleted by a scheduled deletion job.

8. Your rights under Article 11 of the Law

By applying to the data controller, you have the right to:

  • learn whether your personal data is being processed;
  • request information if it has been processed;
  • learn the purpose of processing and whether the data is used in accordance with that purpose;
  • know the third parties to whom your data is transferred, in Turkey or abroad;
  • request rectification if the data is incomplete or incorrect;
  • request erasure or destruction under the conditions in Article 7 of the Law;
  • request that rectification, erasure and destruction be notified to third parties to whom the data was transferred;
  • object to a result adverse to you arising from analysis of your data solely by automated means;
  • claim compensation for damage suffered because of unlawful processing.

9. How to apply

You may submit your requests in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller:

  • in writing, by a signed letter to [Company Address];
  • through a registered electronic mail (KEP) address: [KEP Address];
  • with a secure electronic signature or mobile signature;
  • from the email address you previously notified to us and which is registered in our systems, to [Contact Email].

Your application must state your name and surname, your signature (for written applications), your Turkish ID number (for Turkish citizens) or nationality, passport number or identity number (for foreigners), your address for notification, any email address, telephone and fax number for notification, and the subject of your request.

Your application is concluded free of charge as soon as possible and within thirty days at the latest, depending on the nature of the request; where the process incurs a cost, a fee from the tariff set by the Board may be charged.

If your application is rejected, if you find the response insufficient, or if you receive no response in time, you may lodge a complaint with the Personal Data Protection Board within thirty days of learning of the response and in any case within sixty days of the date of application.

Organisation administrators can export the organisation's data and request its deletion from the Organization › Data screen in the panel.

10. Changes

This notice is updated when our processing activities change, and the date above is refreshed.