MFM Grup Danışmanlık

Privacy and data protection

Privacy Policy and Data Protection Notice

We process personal data only for specific, clear and legitimate purposes, with a commitment to data minimization, security and transparency.

MFM Grup Danışmanlık Limited ŞirketiEffective date: August 9, 2026

01

Scope and roles

This policy applies to the corporate website at www.mfmgrupdanismanlik.com.tr, web and mobile applications published by MFM Grup Danışmanlık Limited Şirketi, and direct communications with us.

Where we operate an application under the instructions of a client organization, that organization may act as the data controller and MFM Grup Danışmanlık Limited Şirketi may act as a data processor. In such cases, the client’s or application-specific privacy notice applies together with this policy. If an application-specific notice contains different or more detailed terms, that notice takes priority for the relevant processing activity.

02

Data controller

The data controller under Türkiye’s Personal Data Protection Law No. 6698 (KVKK) is MFM Grup Danışmanlık Limited Şirketi.

For privacy and personal data requests, contact us at support@mfmgrupdanismanlik.com.tr.

03

Categories of personal data

We process only the data required for the service, application feature or communication you choose to use. Depending on that interaction, the following categories may be involved:

  • Identity and contact data: name, surname, email address, phone number, organization information and the content of messages you send us.
  • Account and service data: user ID, authorization or role, transaction and support records, and content you intentionally add to a service.
  • Device and technical data: IP address, browser, device and operating system, app version, access date and time, crash and security logs, and technical identifiers required to operate the service.
  • Usage data: feature interactions, session and security activity, and application settings such as language preference.
  • Permission-based or sensitive data: location, photos, files, health or clinical information only where required by an application’s core function and expressly described in an application-specific notice.

04

Purposes of processing

Depending on the data category and service used, personal data may be processed for the following specific purposes:

  • Providing the website, applications and requested services; managing user accounts and permissions.
  • Responding to questions, proposals and support requests and managing communications within a business relationship.
  • Protecting information security, preventing unauthorized access and misuse, and resolving errors and performance issues.
  • Improving service quality, usability and business continuity.
  • Meeting contractual and legal obligations and establishing, exercising or defending legal rights.
  • Providing application-specific functionality only after appropriate notice and satisfaction of the applicable legal conditions.

06

Cookies and local storage

The corporate website does not currently place cookies in your browser or use behavioral advertising, analytics or third-party tracking technologies. The language you actively select is kept in first-party local storage under the “mfm-lang” key solely to show the same preference on your next visit. It remains until you change the language or clear your browser data and is not used to identify you or track behavior across visits.

Hosting and security infrastructure may create limited technical access logs, such as IP address, timestamp and browser information, to deliver the service, prevent misuse and diagnose technical issues.

07

Sharing and international transfers

We do not sell personal data or share it for third-party behavioral advertising. Data may be disclosed only to the extent required to provide the service and subject to confidentiality obligations, including to:

  • Hosting, cloud, email, security, error-monitoring and technical support providers.
  • The relevant client organization and its authorized parties when a service is provided on that organization’s behalf.
  • Legal, financial or technical advisers and auditors.
  • Public authorities, courts and other parties authorized by law.
  • Where an overseas service provider is used, transfers are carried out under an adequacy decision, appropriate safeguard or applicable exception provided by Article 9 of the KVKK, together with any required notices.

08

Retention and deletion

We retain data for the period required by its processing purpose and by applicable statutory limitation or retention rules. Our general approach is:

  • Communication and support records: up to 2 years after the last interaction, and longer only where an ongoing contract, dispute or legal obligation requires it.
  • Website access and security logs: generally up to 12 months unless a security incident or legal requirement requires longer retention.
  • Account and service data: for the duration of the account or contractual relationship and the applicable statutory periods thereafter.
  • Application-specific or sensitive data: for the period stated in the relevant application notice.

09

Data security

We apply technical and organizational measures proportionate to risk, including access controls, least-privilege authorization, logging, secure communications, backups, updates and supplier management, to protect personal data against unauthorized access, loss, alteration or disclosure. No system can guarantee absolute security, but we regularly assess identified risks and improve our safeguards.

10

Your rights under the KVKK

Under Article 11 of the KVKK, you may apply to the data controller to exercise the following rights:

  • Learn whether your personal data is processed and request information if it is.
  • Learn the purpose of processing and whether data is used in accordance with that purpose.
  • Know the third parties in Türkiye or abroad to whom data is transferred.
  • Request correction of incomplete or inaccurate data.
  • Request deletion or destruction where the legal conditions are met and request notification of correction or deletion to recipients.
  • Object to an adverse result produced exclusively through automated analysis.
  • Request compensation for damage caused by unlawful processing.

11

Privacy and account deletion requests

Send requests concerning your rights to support@mfmgrupdanismanlik.com.tr with “KVKK Request” in the subject line. Include your name, the subject of the request, the service or application used and contact details for our response. We may request reasonable additional information to verify your identity and relationship to the relevant account.

You may use the same channel to request deletion of your account and associated personal data. If the relevant application also offers an in-app deletion method, you may use that method. Requests are handled as soon as possible and no later than 30 days, subject to fees permitted by applicable law where a request creates an additional cost.

Request data or account deletion

12

Children’s privacy

Unless an application expressly states otherwise, our services are not directed to children. If a specific product requires processing data relating to children, we provide age-appropriate information, any necessary parent or legal guardian process, and additional application-specific safeguards.

13

Policy updates

We may update this policy when our services, applications or legal obligations change. The current text and effective date are published on this page; where appropriate, material changes are also communicated through the website, application or direct communication channels.