Turkish Data Protection Notice (KVKK)

This page is our disclosure/notice under Turkey's personal data protection law - Law No. 6698 on the Protection of Personal Data ("KVKK"). It applies to users whose data is processed under Turkish law and exists to satisfy a specific Turkish legal disclosure requirement; it is not a consent form or contract. For a general, product-focused explanation of our data practices, see the Privacy Policy.

Last updated:

What is KVKK, and why does this page exist

KVKK (Kişisel Verilerin Korunması Kanunu) is Turkey's Law No. 6698 on the Protection of Personal Data, broadly comparable in purpose to the EU's GDPR. Article 10 of KVKK requires data controllers to proactively disclose certain information to individuals whose data they process - regardless of whether that processing is based on consent. This page fulfills that specific disclosure requirement for yazar.io's Turkey-based users and processing activities.

Identity of the data controller

Under KVKK, your personal data is processed by a sole proprietorship operated by MEHMET SAİT ADIBELLİ (business address: Narlıdere, İzmir, Türkiye; tax identification number: 0070668716) acting as the data controller, within the scope described below.

Purposes of processing

Your personal data is processed for the following purposes, to the extent connected to and limited by each purpose:

  • Carrying out membership/account operations (registration, authentication, session management)
  • Providing the yazar.io service (creating and managing books/characters/locations/notes, exporting, publishing an Author Card, publishing a book's Shareable Wiki)
  • Carrying out information security processes
  • Improving service quality and user experience through product analytics (see the "Analytics" legal-basis note below)
  • Considering the short, entirely optional onboarding introduction preferences you share (how you heard about us, what you write, how you'd describe yourself, your country, your first goals) to understand our user base and improve the product
  • Sending commercial electronic messages (news/updates), if you've requested them
  • Fulfilling legal obligations and managing potential disputes

Who your data may be transferred to, and for what purpose

Your personal data may be transferred, limited to the purposes above, to the following parties we work with:

  • Supabase (database, authentication, and file storage provider - hosted in the European Union, Frankfurt/Germany)
  • Vercel (application hosting/server provider)
  • Google Cloud (the key management service - KMS - used to protect the key that encrypts your book content; your creative content itself is never sent to Google Cloud, only a random encryption key that unlocks it reaches this service - a SEPARATE Google service from Google Analytics/Google sign-in below)
  • PostHog (product analytics provider - hosted in the EU region)
  • Google Analytics (secondary product analytics provider, gated by the same consent as PostHog)
  • Google (only if you use the "Continue with Google" option, for authentication - a SEPARATE service from Google Analytics)
  • Crisp (only if you start a live chat yourself, to deliver your support messages)
  • Resend (for delivering account and security emails - NOT marketing email)
  • Sentry (to detect technical errors in the application)
  • Paddle (if you purchase the Yazar Pro paid plan - as our payment service provider and Merchant of Record; simply visiting the Payment, Subscription, and Cancellation Terms page without purchasing can also cause technical connection data such as your IP address/browser information to reach Paddle's infrastructure provider (Cloudflare), because Paddle's script loads in your browser. Paddle is not a processor acting on our instructions for this transfer, but acts in its own name, as an independent controller/recipient, under its own payment, tax, invoicing, fraud-prevention, and regulatory obligations. The specific Paddle entity that contracts with you for a given purchase is determined by your location, as described in Paddle's own Buyer Terms.)

A note on cross-border transfer

Even though some of our providers (Supabase, PostHog) process data within the European Union, this still counts as a cross-border transfer under KVKK Article 9 from a Turkish-law perspective. Following the amendment that took effect on 1 June 2024, a cross-border transfer is lawful if the Board has issued an adequacy decision for the destination, or, absent that, if one of the following safeguards is in place: the Board's announced standard contract, binding corporate rules, or a written undertaking with Board approval.

This is not specific to Paddle - it applies to all of yazar.io's foreign-based providers, including Supabase, Vercel, PostHog, Google, Google Cloud, Crisp, Resend, Sentry, and Paddle. For each provider, the actual data flow, that provider's role in the transfer (a processor acting on our behalf, or an independent controller/recipient like Paddle), and the applicable legal transfer mechanism (e.g. the Board's announced standard contract) will be finalized by legal counsel on a provider-by-provider basis. Having signed a data processing agreement (DPA) with a provider (PostHog, Crisp) does not by itself change this - signing a DPA is NOT the same thing as having a KVKK Article 9 cross-border transfer mechanism (e.g. the Board's standard contract) in place.

Method of collecting personal data

Your personal data is collected electronically, through the registration/login forms you fill out on the yazar.io web application, the information Google shares with our authentication provider if you choose to sign in with Google, your answers to the optional onboarding introduction survey that may appear at your first login, and the electronic records (including analytics events) generated as you use the app.

Your rights under KVKK

Under Article 11 of KVKK, you may apply to us to:

  • Learn whether your personal data is being processed
  • Request information about it, if it has been processed
  • Learn the purpose of processing and whether it's used consistently with that purpose
  • Know the third parties to whom it is transferred, domestically or abroad
  • Request correction of incomplete or inaccurate data
  • Request deletion or destruction of your data under the conditions set out in Article 7 of KVKK
  • Request that correction/deletion/destruction be notified to third parties to whom the data was transferred
  • Object to a result that is to your detriment arising solely from automated analysis of your data
  • Request compensation for damages arising from unlawful processing

How to apply, and contact channel

To exercise your rights under the KVKK, you may contact us at support@yazar.io using the email address registered to your account, as this helps us verify your identity securely. Your request should include your full name, the email address associated with your account, the subject of your request, and sufficient details explaining the request. We may request additional information where necessary to verify your identity. Under Article 13 of KVKK and related legislation, your request will be resolved as soon as possible and no later than thirty days, depending on its nature.