Data Retention and Erasure Policy
Version v1 — effective 29 August 2026
This policy explains how long personal data processed in the Yangın Takip (FireTrack) service is kept, how it is destroyed once the period expires, and how deletion requests work. Read it together with the KVKK Disclosure.
1. Data controller
| Legal name | DEVİCEYE YAZILIM MEDİKAL TEKNOLOJİLER ANONİM ŞİRKETİ |
|---|---|
| MERSIS No | 6141747247 00001 |
| Trade registry | İstanbul Ticaret Odası — Sicil No: 773212-0 |
| Address | Çiftehavuzlar Mah. Eski Londra Asfaltı Cad. No: 151/1F, D2 Blok, 106, 34220 Esenler / İstanbul / Türkiye |
| Phone | 0850 420 37 38 |
| Data protection contact | [email protected] |
2. Principles
- Purpose limitation: data is not kept once the purpose of processing has ended.
- Statutory precedence: even when the purpose has ended, nothing is deleted before the statutory minimum period expires (for example invoice records).
- Anonymisation instead of deletion: records needed for statistics may be kept after the link to the individual is severed.
- Backup lag: a deleted record may remain in backups until the backup cycle expires; backups are destroyed as a whole.
3. Retention periods
| Record type | Retention period | Basis |
|---|---|---|
| Invoice and accounting records | 10 years | Statutory retention under Turkish tax and commercial law |
| Customer and supplier account records | 10 years after the relationship ends | Contractual limitation period |
| Equipment, maintenance and periodic inspection records | 5 years | Evidentiary obligation under fire safety regulation |
| Photographs and signature images | 5 years | Same period as the inspection record they belong to |
| Grace period after an account deletion request | 7 days | Undo window against accidental deletion; data is erased when it expires |
| Audit trail | 2 years | Accountability principle |
| Audit trail of permission and account events | 5 years | Retrospective investigation of security events |
4. Methods of destruction
| Medium | Method |
|---|---|
| Database records | Soft deletion first (the record is withdrawn from use), permanent deletion once the retention period expires. |
| Photographs, signatures and documents | Permanent deletion of the file and its access key from object storage (MinIO). |
| Audit trail entries | Automatic deletion by a scheduled job once expired. |
| Backups | The backup set is destroyed in full when it expires; individual records are not extracted from backups. |
5. Account deletion requests
Account deletion is started from inside the application and requires e-mail verification. After confirmation a 7-day undo window begins, protecting against accidental deletion. When it expires, the tenant's data is permanently deleted.
Statutory exception: invoice and accounting records are retained for 10 years under Turkish tax and commercial law. They are withdrawn from access when the account is deleted and kept solely to meet that obligation.
6. Exporting your data
If you would like a copy of your data before requesting deletion, write to [email protected]; requests are met within 30 days at the latest. The in-app report and Excel export screens can also be used for this purpose.
7. Review
This policy is reviewed at least once a year, and whenever the legislation or our processing activity changes. Current version: v1 (29 August 2026).