KVKK Information Notice

Under Article 10 of Turkish Law No. 6698 (KVKK): which personal data we process, for what purpose and on what legal basis, who we share it with, and your rights.

Last updated: 28 August 2026 · Version v1.6

This notice is issued under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and the related Communiqué on the procedures for fulfilling the duty to inform. For our general practices see the Privacy Policy; for cookies see the Cookie Policy.

1. Identity of the data controller

Data controllerBirileri Dış Ticaret Danışmanlık Sanayi ve Ticaret Limited Şirketi
BrandSmartifie
MERSİS0177070525100001
Trade registry no227539 — Izmir Trade Registry
Tax office / Tax IDKarşıyaka Tax Office / 1770705251
AddressBahariye Mah. 1865 Sk. Karadoğan Blok No: 9, İç Kapı No: 1, Karşıyaka / İZMİR
Phone+90 555 561 45 47
E-mailinfo@smartifie.com
KEPkayacan.kirpikli@hs01.kep.tr
KVKK contact personKayacan Kırpıklı — kayacan.kirpikli@smartifie.com

2. Our role depends on the product variant

Variant Your business data Account, licence, payment, support
Device-local (Windows/Android/iOS/macOS) Stays on your device, never reaches us — you are the controller We are the controller
Cross-platform / cloud On our servers (Türkiye) — we are the processor, you are the controller We are the controller
Custom DB add-on On your own database server; we do not store your credentials and have no access to the data — we are not a party to it (neither controller nor processor); you are the controller We are the controller
To be explicit: even in the device-local variant, licence verification does bring data to us. Saying "no data ever reaches us" would not be true.

3. Personal data we process

CategoryData
IdentityName, surname, (where required for invoicing) national ID / tax number
ContactE-mail, phone, billing address
Customer transactionsProduct/plan purchased, licence records, subscription history, support requests
FinancialPayment records, invoice details (card numbers are not stored by us)
Transaction security / technicalIP address, device and browser information, device fingerprint for licence activation, session and audit logs
Account securityWhether your e-mail is verified; if you enable two-factor authentication, the authenticator secret and recovery codes; a short-lived cookie recording that your password was confirmed recently for a sensitive action; a record if two-factor authentication was reset. No phone number is collected — an authenticator app is used instead of SMS.
Marketing (if any)Only if you give explicit consent: newsletter subscription

4. Purposes and legal bases

PurposeLegal basis (KVKK Art. 5)
Opening the account, issuing and verifying the licence, delivering the productArt. 5/2-c — conclusion/performance of the contract
Taking payment, issuing invoices, accounting recordsArt. 5/2-ç — legal obligation (Tax Procedure Law, Commercial Code)
Handling support requestsArt. 5/2-c — performance of the contract
Preventing licence piracy and abuseArt. 5/2-f — legitimate interest
Account security: e-mail verification, two-factor authentication, password re-confirmation, rate limitingArt. 5/2-f — legitimate interest; Art. 12 — data security obligation. Not based on consent.
Analytics cookies (Google Analytics)EXPLICIT CONSENT
Marketing e-mail (not sent today)EXPLICIT CONSENT + Law 6563 / IYS permission

5. Method of collection

We collect your data electronically and by automated means: through website forms, account creation and sign-in, checkout, licence activation and periodic verification calls, support e-mails, and cookies that depend on your consent.

6. Recipients and transfers abroad

RecipientPurposeCountry
Google Ireland/LLCAnalytics — only with your consentEU/USA
IyzicoTaking payment in TürkiyeTürkiye
PaddleMerchant of Record for sales outside Türkiye: payment, invoice, taxEU / UK
Pentech Bilişim Teknolojileri San. ve Tic. Ltd. Şti.Server hosting (VM) — all data held on the serverTürkiye — Bursa
Google Play · App Store · Trendyol · AmazonDistribution and collection if you purchased via that channelUSA / TR
Competent public authoritiesLegal obligation (Art. 8/2-a)Türkiye

Your data is not sold for marketing.

7. Retention periods

DataPeriod
Invoice, payment, accounting records10 years (Commercial Code Art. 82)
Account, licence, subscription recordsWhile the account exists + 10 years to the extent tied to invoicing
Support correspondence3 years after the request is closed
Audit and security logs — raw IP address90 days; the raw IP is then deleted, only city/country remains. Deletion runs automatically once a day.
Two-factor authentication secret and recovery codesWhile two-factor authentication is on; deleted when it is turned off or reset by our support team
Password confirmation (step-up) cookie15 minutes
Cookie consent recordIn your browser's localStorage, until you delete it

8. Data security

We apply encryption in transit and at rest, access control, logging and regular security audits (KVKK Art. 12). In the event of a data breach we notify the Board within 72 hours and inform you as soon as possible.

Account-specific measures. Starting a trial, buying a plan and linking a device require a verified e-mail address. Two-factor authentication is optional on every account and required for accounts that manage billing, seats or other people's access (authenticator app; no SMS). For sensitive actions such as removing a device or changing billing details, your password is requested again. If you lose both your phone and your recovery codes, our support team can reset two-factor authentication; you are notified by e-mail when this happens.

9. Your rights (KVKK Art. 11)

You have the right to learn whether your personal data is processed; to request information if it is; to learn the purpose of processing and whether the data is used in line with that purpose; to know the third parties to whom it is transferred at home or abroad; to request correction if it is incomplete or inaccurate; to request erasure or destruction where the conditions are met; to request that correction, erasure and destruction be notified to those third parties; to object to a result adverse to you arising from analysis solely by automated systems; and to claim compensation if you suffer damage due to unlawful processing.

You may send your requests to kayacan.kirpikli@@smartifie.com or info@@smartifie.com, or to our registered electronic mail (KEP) address. We respond free of charge within 30 days at the latest. If you find our reply insufficient, you may complain to the Turkish Personal Data Protection Board.

10. Where explicit consent is collected

The duty to inform and explicit consent are fulfilled separately. This page is the information notice only; where explicit consent is required, it is collected on the screen of the relevant action, separately and never pre-ticked: the cookie notice for analytics cookies, the subscription form for commercial e-mail. You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing before it.

11. Free tool pages (online tools that require no account)

Our website offers free tool pages that can be used without an account and without payment: smartifie.com/en/tools. Two tools are live today: the barcode generator and the shipping mark generator. This section applies to all tool pages, present and future, and is disclosure only under KVKK Art. 10 and the Communiqué on the Procedures and Principles for Fulfilling the Disclosure Obligation (RG 10.03.2018-30356). No explicit consent is taken for these pages, and none is required.

11.1. We are not the controller of the data you enter into a tool. Barcode and label generation happens entirely inside your browser, on your own device. The barcode contents, label texts and the spreadsheet file you select are not sent to our servers; the file is not uploaded, it is read in your browser's memory. The images and PDF files produced are also created in your browser.

Because this data never reaches us, no processing (collection) takes place within the meaning of KVKK Art. 3/1-e; neither the controller role (Art. 3/1-ı) nor the processor role (Art. 3/1-ğ) arises.

11.2. The only personal data we process on these pages arises from serving you the page. Web server access log: your IP address, browser and device information, and a timestamp. The purpose is system security, fault diagnosis and abuse prevention; the legal bases are Art. 5/2-f (legitimate interest) and Art. 12 (data security obligation). Period: 14 days — the web server logs are rotated daily, at most 14 copies are retained, and anything older is deleted automatically. In addition an aggregate page counter is kept by day, page path, language, referring source and a bot/human split; because no record linkable to a visitor is kept, no personal data is processed in that respect.

These 14 days are separate from the 90-day row in section 7. That period concerns the audit and security records of users who have an account. For someone visiting a tool page without an account, no such record is created at all.

11.3. Method of collection. The technical records above are collected electronically and by automated means while the page is served to your browser. There is no form submission on a tool page; your inputs are not transmitted to us.

11.4. Transfers. The tool's own operation involves no transfer to any third party, at home or abroad: all software libraries the tool needs are hosted on our own server, no request is sent to any content delivery network (CDN), font provider or script provider, and the data you enter into the tool is not passed to any recipient.

The one exception — analytics measurement (subject to explicit consent). The tool pages use the site's general page layout. If you have given explicit consent to analytics cookies, the Google Analytics script also loads here; your browser sends a request to googletagmanager.com and data about your visit (IP, device/browser information, navigation) is transferred to Google Ireland/LLC (EU/USA), listed in section 6. The basis for the transfer is your explicit consent (Art. 5/1; for transfers abroad, Art. 9). If you have not consented, or you rejected, the script is not added to the page at all and no request is sent. This is not a new transfer specific to the tool pages and it adds no new recipient to the list in section 6; you can withdraw your consent at any time from the Cookie Policy page.

11.5. Third-party data you enter into a tool. If you enter another person's personal data into a tool (for example your customer's name or address in a label text), you are the controller of that data: establishing a legal basis, informing the data subject and, where required, obtaining their explicit consent are your obligations. Because we do not see, receive or store that data, we cannot discharge those obligations on your behalf.

11.6. Cookies and browser-local storage. For their own operation the tool pages write no cookie and use no localStorage or sessionStorage; your inputs and settings are not stored and return to defaults when the page is refreshed. The site-wide strictly necessary cookies and the analytics cookies that load only with your explicit consent are separate from this (see the Cookie Policy); the tool page adds no new cookie to them. The record of your cookie choice falls under that same exception: it is kept in your browser's localStorage (see section 7) and belongs to the site as a whole — even if you answer the cookie banner for the first time on a tool page, that record is not the tool's own.

11.7. Your rights and how to apply. Your KVKK Art. 11 rights set out in section 9 apply to the processing described here as well, and you may apply using the procedure explained there.

12. Changes

We update this notice from time to time; the version number and last-updated date change with every revision. Questions: info@@smartifie.com.

Privacy Policy · Cookie Policy