Turkish Law No. 6698 · Article 10
Privacy Notice
Version 1.3 · Effective 22 September 2026
This notice describes personal-data processing in the Oops! mobile app and web administration panel. Giving this notice does not depend on your approval. A record that you saw it is not explicit consent. The Turkish text is the binding version.
1. Data controller
The data controller is İhsan Kumuma, the natural person who develops and operates Oops!. Oops! is not operated on behalf of a company or public body.
Contact and KVKK applications: ihsanihsankumuma@gmail.com
2. What is processed, why and on which legal ground?
| Activity and data | Purpose and legal ground |
|---|---|
| Account and sign-in: email, user ID, password hash, account/sign-in time, IP address and user agent | Performance of the service contract (Art. 5/2-c) to create your account and session; legitimate interests (Art. 5/2-f) to protect the account and prevent abuse. |
| Password reset: requested email address, one-time reset link and sending/delivery records | Performance of the service contract (Art. 5/2-c) to restore account access; legitimate interests (Art. 5/2-f) to secure the request and delivery. Email verification is not mandatory at sign-up. |
| Profile: name and university; optional short bio and profile photo | Performance of the service contract (Art. 5/2-c) to provide the profile feature you request and identify you to a community you join. Photos are not used for biometric recognition. |
| App choices: communities followed, events saved or joined and action timestamps | Performance of the service contract (Art. 5/2-c) to show your choices and manage attendance and capacity. |
| Community management: managed community, events and images created, and access-code attempts | Performance of the service contract (Art. 5/2-c) to provide management tools; legitimate interests (Art. 5/2-f) to restrict unauthorised access. |
| Optional contact: email and, only if supplied, phone number | Explicit consent (Art. 5/1) for the controller to contact you about cancellations, time/venue changes or emergencies. A separate consent text is provided; refusing does not prevent use of the app. |
| Compliance records: notice version and time presented, contact-consent events, requests and destruction records | Legal obligation (Art. 5/2-ç) and establishment, exercise or protection of a right (Art. 5/2-e) to meet and prove compliance duties. |
Data is collected directly from sign-up and profile forms and automatically when choices and security events occur. Oops! does not ask for special-category data such as health, religion, political opinion or biometrics. It does not collect the device's precise location.
3. Who sees it; who receives it?
- A community admin sees only the name, university, profile photo, relevant attendance and last-activity time of a person who follows their community or joins its event. They cannot see email or phone.
- The data controller and platform admin may access the records necessary to operate the service, handle a security incident or data-subject request, and make optional emergency contact.
- Supabase acts as processor for the database, authentication and file storage in the project's Frankfurt, Germany region.
- Brevo acts as processor for requested password-reset emails, handling the recipient address, one-time link in the message and delivery records. Reset emails are sent only on request.
- Vercel serves the landing and web administration pages and may process IP address, user agent, request path and security/diagnostic logs when the website is visited. Account data in the panel travels directly from the browser to Supabase.
- Competent public authorities may receive only the data covered by a legally valid request.
When you open an external registration link on an event or community page, Oops! does not receive the form response. The community or service operating that form is separately responsible for its own processing.
4. International transfers
Account, profile, choice and image data is transferred to Supabase infrastructure in Germany; password-reset emails and delivery records to Brevo infrastructure in the EU; and website access records to Vercel infrastructure. These are regular transfers and are not based on explicit consent made a condition of the service.
The transfer mechanism required for production use is the controller-to-processor standard contract under Article 9/4-c of the KVKK. It must be signed by the transfer parties and notified to the Authority within five business days after signatures are complete. Opening general registration before this safeguard is completed creates a legal-compliance risk.
5. Retention and destruction
| Record | Maximum period or criterion |
|---|---|
| Account, email and profile | Until account deletion. Removing a profile photo also deletes its file. |
| Phone | Until contact consent is withdrawn, the number is removed from the profile or the account is deleted; withdrawal also deletes the phone field. |
| Follow and save choices | Until the choice is withdrawn or the account is deleted. |
| Past-event attendance | No more than 12 months after the event date. |
| Access-code attempt record | No more than 30 days; earlier after successful use. |
| Withdrawn contact consent and pseudonymised evidence | 3 years for proof and destruction records. |
| Destruction-operation records | At least 3 years from the operation. |
| Password-reset delivery records and email previews | According to the active Brevo account retention rule. A one-month log retention period and no stored email previews are the target settings; they must be verified separately in the provider account. |
| Provider security and access logs | The active provider plan's technical retention period; they are not copied into the app database. |
A nightly task deletes time-limited records. Account deletion removes the profile, follows, attendance, current consent records and profile photo from the active system. Published event or community content belonging to a community may remain, with the link to the user removed. Any provider backup is overwritten when the cycle for the active provider plan expires.
6. Your rights and how to apply
You may exercise the Article 11 rights to information, correction, deletion/destruction, learning recipients, objecting to an automated result and seeking compensation. In the profile screen you can obtain your data in JSON, correct your profile, withdraw contact consent or delete your account.
For other requests, write from the email registered to your account to ihsanihsankumuma@gmail.com. An application must include name and surname; Turkish ID number for Turkish citizens or nationality and passport/identity number for others; service address; email/phone if available; and a clear request. Only information needed to verify identity will be requested.
Applications are answered as soon as possible and within 30 days. A fee may be requested only if an additional cost arises and only under the Authority's tariff. You may complain to the Personal Data Protection Board within 30 days after learning the response and in any event within 60 days after the application.
7. Security and breaches
Profile and attendance data is protected by row-level authorisation; profile photos are served from a private bucket through short-lived signed links. Traffic uses HTTPS. The app contains no advertising, analytics or third-party tracking code.
If personal data is learned to have been obtained unlawfully, the incident is notified to the Authority without delay and within 72 hours, and to affected people as soon as reasonably possible after they are identified.
8. Separate texts and changes
This Privacy Notice is separate from the explicit-consent text. The optional permission is described in the Contact Explicit Consent Text. A material new version is presented in the app or sign-up flow before new processing begins. Feedback recording which notice version was presented at sign-up is retained.