Privacy Notice

Last updated: 11 May 2026Version: 1.1-en-parityDownload PDF

1. Data Controller

The data controller providing PratikYedek services:

  • Trade name: Berhan Tecer (sole proprietorship → corporation transition before Phase 4)
  • KVKK contact: kvkk@pratikyedek.com
  • General contact: destek@pratikyedek.com
  • Web: https://pratikyedek.com
  • VERBİS registration: Will be completed before Phase 4 (launch)

2. What personal data is processed?

A. Identity and contact data

  • Name, surname, email, mobile phone
  • Accounting firm name (CPA tier)
  • Tax ID (VKN) / National ID (TCKN) — CPA + Enterprise tier only
  • Address (for billing)

B. Account security data

  • Password bcrypt hash (plaintext NEVER stored)
  • 2FA TOTP secret (encrypted-at-rest)
  • SMS OTP codes (bcrypt hash, 5-minute TTL)
  • Session info (cookie + JWT)

C. Backup file content

  • Files you upload are end-to-end client-side encrypted (AES-256-GCM)
  • Encryption key stays on your device; PratikYedek never sees plaintext
  • Only encrypted binary blobs are stored in object storage

D. Usage and audit log data

  • IP address, User-Agent (30 days)
  • Session start/end time
  • Backup/restore time, file size (NOT content; metadata only)
  • Account changes (audit_log; KVKK § 12 — 7 years)

E. Mobile-specific data (Android)

  • Device ID — for per-device session management and push token rotation
  • FCM push token — shared with Google for notification delivery (optional; push can be disabled in Settings)
  • App version + Android API level — for compatibility diagnostics

3. Purposes of processing

PurposeLegal basis (KVKK § 5)
Account creation and user managementPerformance of contract — § 5/2-c
Cloud backup service provisionPerformance of contract — § 5/2-c
Billing and subscription managementPerformance of contract — § 5/2-c
Legal accounting record retention (TTK Art. 82 / VUK — 10 years)Legal obligation — § 5/2-a
Error monitoring (GlitchTip self-hosted, Türkiye VDS)Legitimate interest — § 5/2-f
Push notifications (job complete, alert)Explicit consent — § 5/1 (opt-in)

4. Data transfers

A. Domestic sub-processors (Türkiye)

Sub-processorServiceData transferredLocation
GlitchTip self-hostedError monitoringAnonymized error metadataVDS Türkiye
Foribae-Archive invoice (GİB)Invoice data (statutory)Türkiye
PaynKolayPOS / paymentCard masked (PCI-DSS); never storedTürkiye
SMS providers (Kobikom, NetGSM, Turkcell, TT Mesaj, Vodafone)OTP deliveryGSM + OTP codeTürkiye
Cloudflare TR EdgeCDN, DDoSIP + request metadataTürkiye edge nodes

B. International sub-processors (KVKK § 9 — explicit consent)

Sub-processorServiceData transferredLocation
Google (FCM)Android push notificationsFCM token + notification payload (no PII)Global
Google (BYOS Drive — user choice)Individual user backup to own DriveEncrypted binary blobMulti-region
Microsoft (BYOS OneDrive — user choice)Individual user backup to own OneDriveEncrypted binary blobEU

BYOS is forbidden in the CPA tier — your data stays within Türkiye.

C. What is NEVER transferred

  • Plaintext backup file content (end-to-end encryption)
  • Marketing to third parties — never
  • AI training data — never

5. How is your data protected?

  • End-to-end encryption: client-side AES-256-GCM; encryption key only on your device
  • Encryption-at-rest: LUKS dm-crypt (server disk level)
  • Encryption-in-transit: TLS 1.2+ (modern cipher suite)
  • Access control: Row-Level Security (RLS) PostgreSQL; tenant isolation
  • Audit log: All sensitive operations retained 7 years (KVKK § 12)
  • WAL+PITR: 5-minute granularity point-in-time recovery (Postgres 16; pg_receivewal active)
  • Penetration test: Annual (first one before Phase 4; independent third party)
  • VERBİS registration: Completed before Phase 4

6. Retention periods

Data categoryPeriodReason
Account infoFor the lifetime of the account + 30-day cooldownKVKK § 7 deletion request cooldown
Audit log7 yearsKVKK § 12 + audit access
Financial records (billing, taxpayer)10 yearsTTK Art. 82 + VUK
Error logs (GlitchTip)90 daysSelf-hosted retention policy
IP address (request log)30 daysKVKK proportionality
SMS delivery logs1 yearBTK regulation
Test kullanıcı geri bildirimiAnonymized 1 year after test user phase endsTest user retrospective analysis

7. KVKK § 11 — Your rights

You may submit requests via kvkk@pratikyedek.com or the Data Subject Request Form:

  1. Learn whether your personal data is processed
  2. Request information about the processing
  3. Learn the purpose of processing and whether the data is used accordingly
  4. Learn the third parties (domestic/international) to whom data is transferred
  5. Request correction of incomplete or inaccurate data
  6. Under KVKK § 7, request erasure or destruction
  7. Request that correction/erasure operations be reported to third parties
  8. Object to results derived solely from automated analysis that are unfavourable to you
  9. Claim compensation for damages

Response time: 30 days (KVKK § 13/2)

Deletion process: A 30-day cooldown starts when the request is received (KVKK § 7); at the end of the cooldown, actual deletion occurs along with an Ed25519-signed deletion certificate (PDF). Records subject to statutory retention (TTK Art. 82 + VUK 10 years) are not deleted but moved to a separate encrypted archive.

8. Children's privacy

PratikYedek does not provide services to users under 18. If an under-18 registration is detected, the account is deleted immediately and the parent is contacted.

9. Updates to this Privacy Notice

This notice may be updated due to legal or service changes. A notification is sent to your registered email 30 days before the update takes effect.

10. Cookie policy

For details, see the Cookie Policy page.