Oops!

Turkish Law No. 6698 · Article 10

Privacy Notice

Version 1.3 · Effective 22 September 2026

This notice describes personal-data processing in the Oops! mobile app and web administration panel. Giving this notice does not depend on your approval. A record that you saw it is not explicit consent. The Turkish text is the binding version.

1. Data controller

The data controller is İhsan Kumuma, the natural person who develops and operates Oops!. Oops! is not operated on behalf of a company or public body.

Contact and KVKK applications: ihsanihsankumuma@gmail.com

2. What is processed, why and on which legal ground?

Activity and dataPurpose and legal ground
Account and sign-in: email, user ID, password hash, account/sign-in time, IP address and user agentPerformance of the service contract (Art. 5/2-c) to create your account and session; legitimate interests (Art. 5/2-f) to protect the account and prevent abuse.
Password reset: requested email address, one-time reset link and sending/delivery recordsPerformance of the service contract (Art. 5/2-c) to restore account access; legitimate interests (Art. 5/2-f) to secure the request and delivery. Email verification is not mandatory at sign-up.
Profile: name and university; optional short bio and profile photoPerformance of the service contract (Art. 5/2-c) to provide the profile feature you request and identify you to a community you join. Photos are not used for biometric recognition.
App choices: communities followed, events saved or joined and action timestampsPerformance of the service contract (Art. 5/2-c) to show your choices and manage attendance and capacity.
Community management: managed community, events and images created, and access-code attemptsPerformance of the service contract (Art. 5/2-c) to provide management tools; legitimate interests (Art. 5/2-f) to restrict unauthorised access.
Optional contact: email and, only if supplied, phone numberExplicit consent (Art. 5/1) for the controller to contact you about cancellations, time/venue changes or emergencies. A separate consent text is provided; refusing does not prevent use of the app.
Compliance records: notice version and time presented, contact-consent events, requests and destruction recordsLegal obligation (Art. 5/2-ç) and establishment, exercise or protection of a right (Art. 5/2-e) to meet and prove compliance duties.

Data is collected directly from sign-up and profile forms and automatically when choices and security events occur. Oops! does not ask for special-category data such as health, religion, political opinion or biometrics. It does not collect the device's precise location.

3. Who sees it; who receives it?

When you open an external registration link on an event or community page, Oops! does not receive the form response. The community or service operating that form is separately responsible for its own processing.

4. International transfers

Account, profile, choice and image data is transferred to Supabase infrastructure in Germany; password-reset emails and delivery records to Brevo infrastructure in the EU; and website access records to Vercel infrastructure. These are regular transfers and are not based on explicit consent made a condition of the service.

The transfer mechanism required for production use is the controller-to-processor standard contract under Article 9/4-c of the KVKK. It must be signed by the transfer parties and notified to the Authority within five business days after signatures are complete. Opening general registration before this safeguard is completed creates a legal-compliance risk.

5. Retention and destruction

RecordMaximum period or criterion
Account, email and profileUntil account deletion. Removing a profile photo also deletes its file.
PhoneUntil contact consent is withdrawn, the number is removed from the profile or the account is deleted; withdrawal also deletes the phone field.
Follow and save choicesUntil the choice is withdrawn or the account is deleted.
Past-event attendanceNo more than 12 months after the event date.
Access-code attempt recordNo more than 30 days; earlier after successful use.
Withdrawn contact consent and pseudonymised evidence3 years for proof and destruction records.
Destruction-operation recordsAt least 3 years from the operation.
Password-reset delivery records and email previewsAccording to the active Brevo account retention rule. A one-month log retention period and no stored email previews are the target settings; they must be verified separately in the provider account.
Provider security and access logsThe active provider plan's technical retention period; they are not copied into the app database.

A nightly task deletes time-limited records. Account deletion removes the profile, follows, attendance, current consent records and profile photo from the active system. Published event or community content belonging to a community may remain, with the link to the user removed. Any provider backup is overwritten when the cycle for the active provider plan expires.

6. Your rights and how to apply

You may exercise the Article 11 rights to information, correction, deletion/destruction, learning recipients, objecting to an automated result and seeking compensation. In the profile screen you can obtain your data in JSON, correct your profile, withdraw contact consent or delete your account.

For other requests, write from the email registered to your account to ihsanihsankumuma@gmail.com. An application must include name and surname; Turkish ID number for Turkish citizens or nationality and passport/identity number for others; service address; email/phone if available; and a clear request. Only information needed to verify identity will be requested.

Applications are answered as soon as possible and within 30 days. A fee may be requested only if an additional cost arises and only under the Authority's tariff. You may complain to the Personal Data Protection Board within 30 days after learning the response and in any event within 60 days after the application.

7. Security and breaches

Profile and attendance data is protected by row-level authorisation; profile photos are served from a private bucket through short-lived signed links. Traffic uses HTTPS. The app contains no advertising, analytics or third-party tracking code.

If personal data is learned to have been obtained unlawfully, the incident is notified to the Authority without delay and within 72 hours, and to affected people as soon as reasonably possible after they are identified.

8. Separate texts and changes

This Privacy Notice is separate from the explicit-consent text. The optional permission is described in the Contact Explicit Consent Text. A material new version is presented in the app or sign-up flow before new processing begins. Feedback recording which notice version was presented at sign-up is retained.