KVKK Disclosure
Version v1 — effective 29 August 2026
This notice is provided under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and describes how personal data is processed within the Yangın Takip (FireTrack) service offered at yangintakip.com.
1. Identity of the Data Controller
| Legal name | DEVİCEYE YAZILIM MEDİKAL TEKNOLOJİLER ANONİM ŞİRKETİ |
|---|---|
| MERSIS No | 6141747247 00001 |
| Trade registry | İstanbul Ticaret Odası — Sicil No: 773212-0 |
| Address | Çiftehavuzlar Mah. Eski Londra Asfaltı Cad. No: 151/1F, D2 Blok, 106, 34220 Esenler / İstanbul / Türkiye |
| Phone | 0850 420 37 38 · 0545 423 79 31 |
| Data protection contact | [email protected] |
Which data this notice covers
The service is used by fire safety companies to track their own customers and equipment, so there are two distinct relationships:
- Data for which we are the controller: identity, contact, session and billing data of account holders and users. This notice describes that data.
- Data for which the subscribing company is the controller: the customer, site, contact person and field records that the company enters itself. For those records we act as a data processor; informing the individuals and obtaining any required consent is the subscribing company's obligation. We do not access that data other than on instruction.
2. Categories of Personal Data Processed
The categories below are derived from the application's data model; no personal data field outside this list is stored.
| Category | Data included |
|---|---|
| Identity and contact | Full name, e-mail address, phone number, profile image; contact person name, phone and e-mail on customer and site records; name, title and certificate number of training participants. |
| Account and authorisation | User role and tenant membership, password hash, two-factor preference, last sign-in time, interface language, timestamp of terms acceptance. |
| Financial and transactional | Tax number and tax office (for sole traders this field may hold a national ID number), invoice number and ETTN, invoice lines and amounts, account ledger entries, cheque and promissory note records, quote and contract amounts. |
| Location | Site address and the latitude/longitude resolved from it; the coordinates recorded when a periodic inspection is filed. |
| Visual | Equipment and site photographs taken in the field, signature images attached to inspection records, uploaded documents. These files are stored in object storage (MinIO). |
| Security | IP address and browser information (in the audit trail), session and refresh tokens, trusted device records, one-time verification codes, mobile push token with device name and platform. |
No special categories of personal data (health, biometrics, religion, union membership and similar) are collected or processed. Please do not enter such data into free-text fields.
3. Purposes and Legal Grounds
| Purpose | Legal ground (KVKK Art. 5) |
|---|---|
| Creating the account, authentication, authorisation and providing the service | Necessary for the performance of a contract — Art. 5/2-(c) |
| Invoicing the subscription and keeping accounting records | Compliance with a legal obligation — Art. 5/2-(ç) |
| Keeping and reporting equipment, maintenance and inspection records | Performance of a contract — Art. 5/2-(c); legitimate interest in evidentiary needs arising from regulation — Art. 5/2-(f) |
| Account security, prevention of misuse and keeping the audit trail | Legitimate interest — Art. 5/2-(f) |
| Handling support requests and service-related e-mails | Performance of a contract — Art. 5/2-(c) |
| Sending commercial electronic messages for marketing | Explicit consent — Art. 5/1. Withholding consent does not prevent you from using the service; see the Explicit Consent Notice. |
| Transfers to service providers abroad (section 5) | Explicit consent — Art. 9/1 |
4. Methods of Collection
- Sign-up and invitation forms and the data entry screens inside the application (web and mobile).
- QR scanning, photo capture and signature collection performed in the field through the mobile app.
- Bulk uploads by the subscribing company via Excel/CSV import.
- Technical records generated automatically during sign-in and use (audit trail, security tokens).
- Contact and demo request forms on yangintakip.com.
Cookies and similar technologies are covered by the Cookie Policy.
5. Transfers
Within Türkiye
Data is hosted on servers located in Türkiye. Domestic transfer is limited to lawful requests from competent public authorities and to our hosting provider. Your data is never sold or shared with third parties for advertising.
Abroad
Transfers are made to the three providers below only, limited to the stated data and purposes, and based on your explicit consent (KVKK Art. 9):
| Recipient | Country | Data transferred | Purpose |
|---|---|---|---|
| Resend | United States | Recipient name and e-mail address, message body and attachments (invoice and report PDFs) | Delivery of service e-mails |
| OpenStreetMap Nominatim (OSMF) | United Kingdom / EU | Site address text (no person name is sent) | Resolving an address into map coordinates |
| Expo | United States | Mobile push token, platform and device name | Delivering push notifications to the mobile app |
This list was verified against the running code; no transfer is made to any provider outside it. If the list changes, this notice is updated and its version is incremented.
6. Retention and Erasure
| Record type | Retention period | Basis |
|---|---|---|
| Invoice and accounting records | 10 years | Statutory retention under Turkish tax and commercial law |
| Customer and supplier account records | 10 years after the relationship ends | Contractual limitation period |
| Equipment, maintenance and periodic inspection records | 5 years | Evidentiary obligation under fire safety regulation |
| Photographs and signature images | 5 years | Same period as the inspection record they belong to |
| Grace period after an account deletion request | 7 days | Undo window against accidental deletion; data is erased when it expires |
| Audit trail | 2 years | Accountability principle |
| Audit trail of permission and account events | 5 years | Retrospective investigation of security events |
See the Data Retention and Erasure Policy for details.
7. Your Rights under Article 11 of the KVKK
- To learn whether your personal data is processed,
- To request information if it has been processed,
- To learn the purpose of processing and whether it is used accordingly,
- To know the third parties to whom it is transferred, domestically or abroad,
- To request correction of incomplete or inaccurate data and notification of that correction to third parties,
- To request erasure or destruction within the conditions of the law,
- To object to an adverse outcome arising from automated analysis,
- To claim compensation for damage caused by unlawful processing.
8. How to Apply
Send your request by e-mail to [email protected] or in writing to the postal address above. Your application must contain information identifying you and state your request clearly. Applications are answered within 30 days at the latest; where the request requires additional cost, the fee set by the Board may apply.
For records entered by a subscribing company, the request should be directed to that company; if it reaches us, we forward it and inform you.
9. Updates
This notice is versioned. The current version is v1, effective 29 August 2026. On a material change the version is incremented and registered users are informed.
Related documents: Explicit Consent Notice, Privacy Policy, Data Retention and Erasure Policy, User Agreement.