01
Scope and roles
This policy applies to the corporate website at www.mfmgrupdanismanlik.com.tr, web and mobile applications published by MFM Grup Danışmanlık Limited Şirketi, and direct communications with us.
Where we operate an application under the instructions of a client organization, that organization may act as the data controller and MFM Grup Danışmanlık Limited Şirketi may act as a data processor. In such cases, the client’s or application-specific privacy notice applies together with this policy. If an application-specific notice contains different or more detailed terms, that notice takes priority for the relevant processing activity.
02
Data controller
The data controller under Türkiye’s Personal Data Protection Law No. 6698 (KVKK) is MFM Grup Danışmanlık Limited Şirketi.
For privacy and personal data requests, contact us at support@mfmgrupdanismanlik.com.tr.
03
Categories of personal data
We process only the data required for the service, application feature or communication you choose to use. Depending on that interaction, the following categories may be involved:
- Identity and contact data: name, surname, email address, phone number, organization information and the content of messages you send us.
- Account and service data: user ID, authorization or role, transaction and support records, and content you intentionally add to a service.
- Device and technical data: IP address, browser, device and operating system, app version, access date and time, crash and security logs, and technical identifiers required to operate the service.
- Usage data: feature interactions, session and security activity, and application settings such as language preference.
- Permission-based or sensitive data: location, photos, files, health or clinical information only where required by an application’s core function and expressly described in an application-specific notice.
04
Purposes of processing
Depending on the data category and service used, personal data may be processed for the following specific purposes:
- Providing the website, applications and requested services; managing user accounts and permissions.
- Responding to questions, proposals and support requests and managing communications within a business relationship.
- Protecting information security, preventing unauthorized access and misuse, and resolving errors and performance issues.
- Improving service quality, usability and business continuity.
- Meeting contractual and legal obligations and establishing, exercising or defending legal rights.
- Providing application-specific functionality only after appropriate notice and satisfaction of the applicable legal conditions.
05
Collection methods and legal bases
Data may be collected through website and application use, email communications, application forms and permissions, device and security logs, support processes, client organizations or authorized integrations, by automated or partly automated means or by non-automated means forming part of a filing system.
Depending on the activity, processing relies on an appropriate legal basis under Articles 5 and 6 of the KVKK, including necessity for entering into or performing a contract, compliance with a legal obligation, establishment or protection of a right, legitimate interests that do not override fundamental rights, and explicit consent where required. Sensitive personal data is processed only when the conditions under Article 6 and the necessary safeguards are in place.
08
Retention and deletion
We retain data for the period required by its processing purpose and by applicable statutory limitation or retention rules. Our general approach is:
- Communication and support records: up to 2 years after the last interaction, and longer only where an ongoing contract, dispute or legal obligation requires it.
- Website access and security logs: generally up to 12 months unless a security incident or legal requirement requires longer retention.
- Account and service data: for the duration of the account or contractual relationship and the applicable statutory periods thereafter.
- Application-specific or sensitive data: for the period stated in the relevant application notice.
09
Data security
We apply technical and organizational measures proportionate to risk, including access controls, least-privilege authorization, logging, secure communications, backups, updates and supplier management, to protect personal data against unauthorized access, loss, alteration or disclosure. No system can guarantee absolute security, but we regularly assess identified risks and improve our safeguards.
10
Your rights under the KVKK
Under Article 11 of the KVKK, you may apply to the data controller to exercise the following rights:
- Learn whether your personal data is processed and request information if it is.
- Learn the purpose of processing and whether data is used in accordance with that purpose.
- Know the third parties in Türkiye or abroad to whom data is transferred.
- Request correction of incomplete or inaccurate data.
- Request deletion or destruction where the legal conditions are met and request notification of correction or deletion to recipients.
- Object to an adverse result produced exclusively through automated analysis.
- Request compensation for damage caused by unlawful processing.
11
Privacy and account deletion requests
Send requests concerning your rights to support@mfmgrupdanismanlik.com.tr with “KVKK Request” in the subject line. Include your name, the subject of the request, the service or application used and contact details for our response. We may request reasonable additional information to verify your identity and relationship to the relevant account.
You may use the same channel to request deletion of your account and associated personal data. If the relevant application also offers an in-app deletion method, you may use that method. Requests are handled as soon as possible and no later than 30 days, subject to fees permitted by applicable law where a request creates an additional cost.
12
Children’s privacy
Unless an application expressly states otherwise, our services are not directed to children. If a specific product requires processing data relating to children, we provide age-appropriate information, any necessary parent or legal guardian process, and additional application-specific safeguards.
13
Policy updates
We may update this policy when our services, applications or legal obligations change. The current text and effective date are published on this page; where appropriate, material changes are also communicated through the website, application or direct communication channels.
