Privacy Policy

Privacy notice under KVKK & GDPR

Which personal data we process, for what purposes and on what legal basis; retention periods, disclosure, international transfers and your rights. KVKK and GDPR are addressed together.

Version
Draft v0.1
Updated
13 September 2026
Applicable region
TürkiyeEuropean UnionGlobal
Legal basis
KVKK (Turkish Personal Data Protection Law) · GDPR · ePrivacy
Who it is for
Website visitors, product users, and representatives of customers and suppliers.
Pending legal review. This text is a working draft; fields in square brackets will be filled with project and company details and reviewed by legal counsel before publication. The binding version is the signed agreement.
CM Apps · Privacy PolicyDraft v0.1 · 13 September 2026

1. Data controller

The data controller under this policy is [COMPANY LEGAL NAME] (“CM Apps”), address: [ADDRESS], email: [EMAIL]. For data subjects established in the European Union, where required under Article 27 of the GDPR, the EU representative is: [EU REPRESENTATIVE].

Where we process data belonging to our customers’ own end users through our Products, CM Apps acts as a “data processor”; this relationship is governed by the Data Processing Agreement.

2. Data we process

Identity and contact details (first name, last name, email, phone, job title, company), account and usage data (login records, preferences, in-product activity), commercial information (quotations, contracts, invoices), technical data (IP address, device and browser information, cookie identifiers) and support correspondence.

We do not process special categories of personal data unless it is necessary for the service and we have your explicit consent.

3. Purposes of processing and legal bases

Formation and performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b): account creation, provision of the service, invoicing. Compliance with legal obligations (KVKK Art. 5/2-ç; GDPR Art. 6/1-c): tax, accounting and record-keeping obligations. Legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6/1-f): security, fraud prevention, service improvement. Explicit consent (KVKK Art. 5/1; GDPR Art. 6/1-a): marketing communications and non-essential cookies.

4. Cookies and similar technologies

Our website may use essential, preference, analytics and marketing cookies. Non-essential cookies operate only with your consent. Details are set out in the Cookie Policy.

5. Sharing of data

Your data is shared with sub-processors that provide hosting, email, payment, analytics and support tools, to the extent necessary to deliver the service. The current list is published in the Sub-processor List.

Data may be shared with competent public authorities where legally required, and with the relevant parties in the event of a merger, acquisition or transfer of assets, subject to confidentiality obligations.

6. International transfers

For data subjects established in Türkiye, transfers abroad are carried out in accordance with KVKK Art. 9, using whichever of the following mechanisms is appropriate: an adequacy decision, standard contractual clauses or explicit consent.

For data subjects established in the EU, transfers outside the EEA are made under Chapter V of the GDPR with appropriate safeguards such as an adequacy decision (GDPR Art. 45) or Standard Contractual Clauses (GDPR Art. 46). The mechanism used and the location of each sub-processor are specified in the Sub-processor List.

7. Retention periods

We retain data for as long as required by the purpose of processing and by statutory retention obligations. Commercial books and invoice records are kept for [10] years; contract records for the limitation period; account data for [90] days after the account is closed; marketing consents until withdrawn. At the end of the period, data is deleted, destroyed or anonymized.

8. Security

We protect your data against unauthorized access, loss and misuse through technical and organizational measures such as access control, encryption, backups, logging and staff training. In the event of a data breach, we notify within the periods prescribed by law (KVKK: the Board within 72 hours; GDPR Art. 33: the supervisory authority within 72 hours).

9. Your rights

Under KVKK Art. 11 and GDPR Articles 15 to 22, you have the right to access, rectify and erase your data, to restrict processing, to object, to data portability and to withdraw consent you have given.

You may submit your requests in writing to [EMAIL] or to [ADDRESS]. Requests are concluded within 30 days at the latest (1 month under the GDPR). You may lodge a complaint with the Personal Data Protection Board in Türkiye; data subjects established in the EU may complain to the supervisory authority of their country.

10. Children

Our services are not directed at persons under 18; we do not knowingly collect data from children.

11. Updates

This policy was updated on [13 September 2026]. Changes are published on the website; material changes are also notified separately.

This document is part of the CM Apps Agreements & Policies center. In case of conflict with other documents, the order of precedence is set out in the relevant agreement.

FROM THE SAME CATEGORY

Related documents.

All documents

Have a question about this document?

Write to us for adaptation by scope, region or product.

[email protected]