Turkish Data Protection Notice (KVKK)
This page is our disclosure/notice under Turkey's personal data protection law - Law No. 6698 on the Protection of Personal Data ("KVKK"). It applies to users whose data is processed under Turkish law and exists to satisfy a specific Turkish legal disclosure requirement; it is not a consent form or contract. For a general, product-focused explanation of our data practices, see the Privacy Policy.
Last updated:
What is KVKK, and why does this page exist
KVKK (Kişisel Verilerin Korunması Kanunu) is Turkey's Law No. 6698 on the Protection of Personal Data, broadly comparable in purpose to the EU's GDPR. Article 10 of KVKK requires data controllers to proactively disclose certain information to individuals whose data they process - regardless of whether that processing is based on consent. This page fulfills that specific disclosure requirement for yazar.io's Turkey-based users and processing activities.
Identity of the data controller
Under KVKK, your personal data is processed by a sole proprietorship operated by MEHMET SAİT ADIBELLİ (business address: Narlıdere, İzmir, Türkiye; tax identification number: 0070668716) acting as the data controller, within the scope described below.
Purposes of processing
Your personal data is processed for the following purposes, to the extent connected to and limited by each purpose:
- Carrying out membership/account operations (registration, authentication, session management)
- Providing the yazar.io service (creating and managing books/characters/locations/notes, exporting, publishing an Author Card, publishing a book's Shareable Wiki)
- Carrying out information security processes
- Improving service quality and user experience through product analytics (see the "Analytics" legal-basis note below)
- Considering the short, entirely optional onboarding introduction preferences you share (how you heard about us, what you write, how you'd describe yourself, your country, your first goals) to understand our user base and improve the product
- Sending commercial electronic messages (news/updates), if you've requested them
- Fulfilling legal obligations and managing potential disputes
Who your data may be transferred to, and for what purpose
Your personal data may be transferred, limited to the purposes above, to the following parties we work with:
- Supabase (database, authentication, and file storage provider - hosted in the European Union, Frankfurt/Germany)
- Vercel (application hosting/server provider)
- Google Cloud (the key management service - KMS - used to protect the key that encrypts your book content; your creative content itself is never sent to Google Cloud, only a random encryption key that unlocks it reaches this service - a SEPARATE Google service from Google Analytics/Google sign-in below)
- PostHog (product analytics provider - hosted in the EU region)
- Google Analytics (secondary product analytics provider, gated by the same consent as PostHog)
- Google (only if you use the "Continue with Google" option, for authentication - a SEPARATE service from Google Analytics)
- Crisp (only if you start a live chat yourself, to deliver your support messages)
- Resend (for delivering account and security emails - NOT marketing email)
- Sentry (to detect technical errors in the application)
- Paddle (if you purchase the Yazar Pro paid plan - as our payment service provider and Merchant of Record; simply visiting the Payment, Subscription, and Cancellation Terms page without purchasing can also cause technical connection data such as your IP address/browser information to reach Paddle's infrastructure provider (Cloudflare), because Paddle's script loads in your browser. Paddle is not a processor acting on our instructions for this transfer, but acts in its own name, as an independent controller/recipient, under its own payment, tax, invoicing, fraud-prevention, and regulatory obligations. The specific Paddle entity that contracts with you for a given purchase is determined by your location, as described in Paddle's own Buyer Terms.)
A note on cross-border transfer
Even though some of our providers (Supabase, PostHog) process data within the European Union, this still counts as a cross-border transfer under KVKK Article 9 from a Turkish-law perspective. Following the amendment that took effect on 1 June 2024, a cross-border transfer is lawful if the Board has issued an adequacy decision for the destination, or, absent that, if one of the following safeguards is in place: the Board's announced standard contract, binding corporate rules, or a written undertaking with Board approval.
This is not specific to Paddle - it applies to all of yazar.io's foreign-based providers, including Supabase, Vercel, PostHog, Google, Google Cloud, Crisp, Resend, Sentry, and Paddle. For each provider, the actual data flow, that provider's role in the transfer (a processor acting on our behalf, or an independent controller/recipient like Paddle), and the applicable legal transfer mechanism (e.g. the Board's announced standard contract) will be finalized by legal counsel on a provider-by-provider basis. Having signed a data processing agreement (DPA) with a provider (PostHog, Crisp) does not by itself change this - signing a DPA is NOT the same thing as having a KVKK Article 9 cross-border transfer mechanism (e.g. the Board's standard contract) in place.
Method of collecting personal data
Your personal data is collected electronically, through the registration/login forms you fill out on the yazar.io web application, the information Google shares with our authentication provider if you choose to sign in with Google, your answers to the optional onboarding introduction survey that may appear at your first login, and the electronic records (including analytics events) generated as you use the app.
Legal grounds
Your personal data is processed based on the legal grounds set out in Articles 5 and 6 of KVKK, assessed separately for each purpose:
- Required account operations (registration, login, session management, account/security notice emails - including those sent via Resend): necessary for the establishment or performance of a contract (KVKK Art. 5/2-c) and necessary for the controller to fulfil its legal obligations (Art. 5/2-ç).
- Security (file validation, session security, abuse prevention, detecting technical errors via Sentry, storing your book content encrypted in the database and separately protecting the key that decrypts it with Google Cloud KMS): necessary for the controller's legitimate interests, provided this does not harm your fundamental rights and freedoms (Art. 5/2-f).
- Service delivery (storing/displaying your content, publishing your Author Card): directly related to the establishment or performance of a contract (Art. 5/2-c).
- Analytics: your explicit consent (Art. 5/1) - PostHog/Google Analytics only load if you actively approve the Analytics category in the cookie consent banner; if you don't, they never run. In addition, only structural, non-identifying data is used, and no user content is ever processed.
- Onboarding introduction preferences: preference and profile information you optionally share as part of onboarding (how you heard about us, what you write, your writing experience level, your country code, your first goals) is processed based on your explicit consent under Article 5, paragraph 1 of Law No. 6698. Sharing this information is NOT a condition of using the service - you continue to have full access to yazar.io even if you don't consent.
- Processing your payment if you purchase Yazar Pro (the paid plan): directly related to the establishment or performance of a contract (Art. 5/2-c). Paddle separately processes data in this process, in its own name, as an independent controller, under its own legal obligations (tax, accounting, fraud prevention, regulatory compliance) - see "Who your data may be transferred to" above.
- If you gift Yazar Pro to another Yazar.io user: the gift is a one-time purchase (not a subscription, does not renew automatically, valid for 1 year). Payment is processed through Paddle; you are the payer and the Paddle customer. The recipient's email address is NOT transferred to Paddle - only an unguessable reference code that lets us resolve which gift a payment belongs to is sent to Paddle. Your display name from your profile and (if you write one) your optional gift note are shown to the recipient; your email address is not shared with the recipient. For our team's internal tracking of the gift, your sender email is recorded only in an internal note in our admin panel (not shown to the recipient or any third party).
- Marketing email consent: your explicit consent (Art. 5/1) - a separate, optional consent, entirely independent from creating an account, as explained further below.
The difference between consent and this notice
This document is a NOTICE, not a request for CONSENT - reading this page, or checking the related box on the sign-up form, does not mean you have consented to "any and all" processing of your data. The disclosure obligation is fulfilled separately and independently for every processing activity, whether or not that activity requires consent.
There are THREE processing activities that rely on your explicit consent: (1) the optional commercial email (news/updates), (2) processing the optional onboarding introduction/preference information you choose to share, and (3) analytics - all three are entirely independent from each other and from creating an account, and you can withdraw each one separately at any time. Every other processing activity (account, security, service delivery) relies on the other legal grounds above and does not require a separate consent from you.
Your rights under KVKK
Under Article 11 of KVKK, you may apply to us to:
- Learn whether your personal data is being processed
- Request information about it, if it has been processed
- Learn the purpose of processing and whether it's used consistently with that purpose
- Know the third parties to whom it is transferred, domestically or abroad
- Request correction of incomplete or inaccurate data
- Request deletion or destruction of your data under the conditions set out in Article 7 of KVKK
- Request that correction/deletion/destruction be notified to third parties to whom the data was transferred
- Object to a result that is to your detriment arising solely from automated analysis of your data
- Request compensation for damages arising from unlawful processing
How to apply, and contact channel
To exercise your rights under the KVKK, you may contact us at support@yazar.io using the email address registered to your account, as this helps us verify your identity securely. Your request should include your full name, the email address associated with your account, the subject of your request, and sufficient details explaining the request. We may request additional information where necessary to verify your identity. Under Article 13 of KVKK and related legislation, your request will be resolved as soon as possible and no later than thirty days, depending on its nature.