KVKK Disclosure Notice
Last updated:
This notice has been prepared in accordance with Article 10 of Law No. 6698 on the Protection of Personal Data ("KVKK" or the "Law") and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform, in order to provide information about the personal data processed in connection with the DuyApp mobile application and the duyapp.com website.
Summary
- Personal data is processed for account creation, showing location-based content, publishing content, messaging, artificial intelligence features, notifications and security. Records that must be kept or shared under legal obligations are described separately.
- Anonymous posts are linked to the account that made the post within the DuyApp system. An anonymous post means that this account information is not shown to other users.
- A hosting service provider is used for the application's main server and database. Providers located abroad are used for artificial intelligence, media storage, email, notification, GIF, map and website services. The data transferred and the purposes of transfer are stated in this notice.
- The rights under Article 11 of the Law can be exercised through the methods in the Rights and requests section.
This notice is not a request for explicit consent. The purposes of processing and the legal grounds for them are explained in this notice. For any processing that requires explicit consent, the information and consent procedures are carried out separately. Notice that this text has been read does not mean that approval or explicit consent has been given for all of the processing described in it.
Data controller
The data controller is DUYAPP YAZILIM LİMİTED ŞİRKETİ, the company that operates DuyApp.
Address: Liman Mah. Boğaçayi Cad. No: 30 İç Kapı No: 14 Konyaaltı/Antalya
Email: destek@duyapp.com
Processing activities
The headings below describe the data processed, the purposes of use, the methods of collection and the retention conditions. For special categories of personal data, the relevant section of this notice also applies.
1. Account creation and login
- Data: University email address, email verification code, username, the public key of the passkey, device type, usage times and account recovery records.
- Purpose: Creating the account, verifying the university email address, logging in to the account and recovering the account.
- Legal ground: Processing is necessary for the establishment and performance of a contract (Art. 5/2-c).
- Method of collection: Through information the user enters into the application and passkey records transmitted by the device, by electronic means and automatically.
- Retention period: The verification code is kept for 10 minutes; other account and login data is kept for as long as the account is open.
2. Profile
- Data: Nickname, biography, profile photo, join date, profile and privacy settings.
- Purpose: Creating the profile, showing the user under their nickname and applying profile preferences.
- Legal ground: Processing is necessary for the performance of a contract (Art. 5/2-c).
- Method of collection: From information the user provides in the application and from account records, by electronic means and automatically.
- Retention period: For as long as the account is open.
3. Session security and traffic logs
- Data: IP address, device and browser information (user agent), device name, and the start, last use and end times of sessions.
- Purpose: Ensuring account security, preventing unauthorized access and fulfilling traffic log obligations under Law No. 5651 on Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications.
- Legal ground: Legitimate interest for account and service security (Art. 5/2-f). For records within the scope of the statutory traffic log obligation, the processing is expressly provided for by law and necessary for compliance with a legal obligation (Art. 5/2-a and Art. 5/2-ç).
- Method of collection: Automatically by the server when users log in to the application and use sessions.
- Retention period: Ordinary session records kept for security purposes, together with the IP and device information associated with them, are deleted within 30 days at the latest after the session expires or is revoked. These records may be deleted earlier during the account deletion process. Separate retention conditions apply to statutory traffic logs.
4. Location
- Data: The location obtained from the device while the application is in use; the neighbourhood, district, city, university and campus determined from that location; the rounded map point of posts chosen to be shown on the map, and the preferred campus.
- Purpose: Showing content in the area where the user is located, associating posts with the correct area, providing the map feature, and showing campus-specific content and notifications.
- Legal ground: Processing is necessary to provide the location-based service (Art. 5/2-c).
- Method of collection: Through the device location service that the user permits and from map selections in the application, by electronic means and automatically. Device location is obtained while the application is open; location is not obtained in the background. The location permission in the operating system does not replace explicit consent for any kind of processing under the Law.
- Retention period: Precise location for 15 minutes at most; the area information associated with content for as long as the relevant content is kept; the map point until the post is deleted; the preferred campus for as long as the account is open.
5. Publishing content
- Data: Posts, comments, polls, photos and GIFs shared under a nickname or anonymously; votes cast, poll answers and saved posts.
- Purpose: Publishing content and providing the features of voting, taking part in polls, commenting and saving posts.
- Legal ground: Processing is necessary for the performance of a contract (Art. 5/2-c). For content kept separately because of a complaint or a legal dispute, the legal grounds in section 12 apply.
- Method of collection: From the content the user shares in the application and the actions the user performs, by electronic means and automatically.
- Retention period: Published content and interaction records are kept for as long as the account is open. Deleting a post or comment in the app hides it from other users. This does not remove its text and photo copies from active systems at the same time; copies may remain until account deletion or completion of a separate personal-data deletion request. You can submit a separate deletion request using the contact address in this notice. Deletions are carried out in fulfilment of a legal obligation (Art. 5/2-ç). Evidence copies relating to a specific complaint, a legal dispute or a binding preservation obligation may be kept separately, only to the extent and for the period necessary; the legal grounds in sections 12 and 13 apply to these records. The retention period of backup copies applies separately.
6. Linking anonymous content to the account
- Data: The account to which the anonymous content belongs and the link between the content and the account.
- Purpose: Preventing abuse, examining complaints, enforcing the community guidelines and responding to properly made requests from competent authorities.
- Legal ground: Legitimate interest for preventing abuse and ensuring community safety (Art. 5/2-f); the establishment, exercise or protection of a right for asserting or defending legal claims (Art. 5/2-e); and compliance with a legal obligation for responding to binding requests from competent authorities (Art. 5/2-ç).
- Method of collection: Automatically by the server when anonymous content is shared.
- Retention period: For as long as the relevant content is kept.
7. Duy Points and invitations
- Data: Overall and area-based Duy Points, the vote records that make up the points, the invitation code, and the link between the inviting account and the invited account.
- Purpose: Calculating Duy Points and providing the invitation feature.
- Legal ground: Processing is necessary for the performance of a contract (Art. 5/2-c).
- Method of collection: Through actions in the application and the use of the invitation code, by electronic means and automatically.
- Retention period: For as long as the account is open.
8. Private messages
- Data: End-to-end encrypted message contents, the participants of the conversation, message times, read status and the post to which the conversation relates.
- Purpose: Delivering messages to the recipient and providing the messaging feature.
- Legal ground: Processing is necessary for the performance of a contract (Art. 5/2-c).
- Method of collection: From the messages the user sends and the records created during messaging, by electronic means and automatically.
- Retention period: Encrypted messages held on the server are kept for 30 days at most; unanswered message requests for 14 days. Conversation records are kept for as long as the account of at least one of the participants exists. The link between a participant who deletes their account and that account is removed during the deletion process. The remaining conversation records are deleted within 30 days at the latest after both accounts have been deleted. The retention conditions for evidence set aside for a specific complaint or legal process apply separately.
DuyApp cannot read end-to-end encrypted messages. However, when a user forwards to the moderation team messages that the user has reported, the contents of the forwarded messages become accessible for the examination of the complaint. The processing of these records is described in section 12.
9. Artificial intelligence features (Duyu)
- Data: Duyu chat messages and chat history, the area and time zone from which questions are asked, Duyu Fun scenario texts, comments, and the area in which the comments are made.
- Purpose: Providing the Duyu chat and Duyu Fun features that the user uses.
- Legal ground: Processing is necessary to provide the artificial intelligence service the user requests (Art. 5/2-c). This legal ground does not apply on its own to special categories of personal data.
- Method of collection: From the texts the user writes to Duyu and the records created while using the feature, by electronic means and automatically.
- Retention period: Duyu chats in the DuyApp system until the account is deleted; Duyu Fun content until it is deleted by the user or the account is deleted.
Duyu chat is separate from the end-to-end encrypted private messaging between users. Texts sent to Duyu are transmitted to the artificial intelligence service provider so that a response can be generated.
10. Use of posts in Duyu
- Data: The texts of posts shared under a nickname and suitable for use in Duyu, the area in which they were shared and the times of sharing. Anonymous posts are not included in search and summarization.
- Purpose: Enabling Duyu to search posts in the area and to summarize what is being discussed in the area.
- Method of collection: From posts published in the application, by electronic means and automatically.
- Retention period: For as long as the post is kept. When a post is deleted, it is also removed from the search index.
Email addresses, phone numbers, T.C. identity numbers, IBANs and card numbers that are detected automatically are masked in the text. Anonymous posts are not included in the search index or area summaries. Masking does not in every case remove the character of the text as personal data. A post being accessible does not permit the reuse of personal data for all artificial intelligence purposes. The licence granted for publishing the content and the legal ground for processing personal data are assessed separately.
11. Notifications
- Data: Notification key (push token), device platform, language, time zone, application version, installation ID and notification preferences.
- Purpose: Delivering application notifications according to the user's preferences.
- Legal ground: Processing is necessary to provide the notification service (Art. 5/2-c).
- Method of collection: From information transmitted by the device when notification permission is granted and from preferences in the application, by electronic means and automatically.
- Retention period: Until notifications are turned off or the account is deleted.
12. Moderation, complaints and blocking
- Data: The reporting and reported accounts, the reported content, the reason for and description of the complaint, the account to which anonymous content belongs, private messages that the user forwards to the moderation team together with the complaint, and blocking records.
- Purpose: Examining complaints, enforcing the community guidelines, giving effect to blocking preferences, preventing abuse and preserving evidence in legal disputes.
- Legal ground: Legitimate interest for community safety and preventing abuse (Art. 5/2-f); the establishment, exercise or protection of a right for asserting or defending legal claims (Art. 5/2-e); performance of a contract for giving effect to the user's blocking preference (Art. 5/2-c).
- Method of collection: From the user's complaint and blocking actions, the descriptions and messages the user forwards, and the existing records of the reported content, by electronic means and partly automatically.
- Retention period: Evidence copies of private messages forwarded with a complaint are kept for 90 days from the creation of the evidence record; private message complaint records are kept for 365 days from the creation of the complaint record. Other content complaint records are kept for 365 days from the date on which the file was closed, whether by action being taken or by rejection. If a file is reopened, this period is calculated from the date on which it is closed again. These periods do not mean that all deleted content is kept in general. Blocking records are kept until the relevant account is deleted.
13. Requests from competent authorities
- Data: Account, content, transaction and traffic records within the scope of a properly made request.
- Purpose: Responding to binding requests from judicial authorities and competent public institutions and fulfilling obligations under Law No. 5651.
- Legal ground: Processing is expressly provided for by law and necessary for compliance with a legal obligation (Art. 5/2-a and Art. 5/2-ç).
- Method of collection: From the request received from the competent authority and the existing records in the DuyApp system, in electronic or written form, partly by automatic means.
- Retention period: The period stated for the relevant data category. Records subject to a binding preservation obligation are kept for the period that obligation requires.
14. Support and applications
- Data: Email address, the content of correspondence and information submitted with the application. For applications made to exercise rights under the Law, the identity and contact information required by the application legislation is also processed.
- Purpose: Responding to support requests, verifying that an application belongs to the person concerned, and concluding requests made under the Law.
- Legal ground: Performance of a contract for responding to service-related support requests (Art. 5/2-c); legitimate interest for keeping concluded ordinary support correspondence for a limited period to follow up recurring problems (Art. 5/2-f); compliance with a legal obligation for responding to applications under the Law (Art. 5/2-ç). The establishment, exercise or protection of a right (Art. 5/2-e) is the basis for keeping the records necessary to prove the response given to an application and the actions taken.
- Method of collection: Through email or written application, in electronic or physical form, wholly or partly by automatic means, or by non-automatic means as part of a data filing system.
- Retention period: Ordinary support correspondence is kept for 6 months from the closing of the request and then deleted. The minimum application, response, date and transmission records showing that an application under the Law was handled are kept for 3 years from the giving of the final response and then deleted. Unnecessary attachments are deleted without waiting for the end of this period. If there is a specific dispute or a binding retention obligation, only the relevant records are kept separately for as long as necessary. The three-year application record period is not a general minimum period set by law for all correspondence.
15. Website security
- Data: IP address, browser information and access times.
- Purpose: Ensuring the security of the website and preventing abuse.
- Legal ground: Legitimate interest in ensuring the security of the website (Art. 5/2-f).
- Method of collection: During access to the site, by electronic means and automatically.
- Retention period: Site access and error logs under DuyApp's control are kept for 30 days at most from their creation. Records set aside in connection with a specific security incident or a binding preservation obligation are kept only for the relevant purpose and for the necessary period.
User content and special categories of personal data
DuyApp does not request special categories of personal data, such as health, religion, political opinion, sexual life, or biometric or genetic data, in order to create an account or use the service. However, such information may appear in user content, chats or complaints. The fact that this information appears within text or images rather than in a separate field does not change its status as special categories of personal data.
Where users make their own special categories of personal data public, this data can be processed only within a scope consistent with the intention to make it public (Art. 6/3-ç). This provision does not permit the sharing of data belonging to another person or provide a general permission for any subsequent use. Posting in a limited community, sending a private message or writing information to Duyu is not, on its own, regarded as making data public or as explicit consent.
Special categories of personal data that are necessary for handling complaints and legal disputes are processed within the scope of the establishment, exercise or protection of a right (Art. 6/3-d). This data is not used for profiling individuals, recommendations or advertising targeting.
Automated processing
The ranking of content, the determination of featured content and the safety review of content generated in Duyu Fun are carried out by automated systems. Decisions to suspend or close accounts are made by the moderation team.
Users may object under Article 11 of the Law to a result against them that arises solely from analysis carried out by automated systems.
Transfer of personal data
Sharing with other users
Published content and the name of the area with which the content is associated can be seen by other users. For posts made under a nickname, the selected profile information is shown. For anonymous posts, the profile information of the account that published the content is not shown.
Transfers within Türkiye
- Judicial authorities and competent public institutions. Data within the scope of properly made and binding requests is shared in order to respond to them.
For these transfers, Article 8 of the Law and the legal grounds stated for the relevant processing activity apply. For the transfer of special categories of personal data, the conditions in Article 6 of the Law are also required.
Transfers abroad
The data transmitted to service providers abroad and the purposes of transfer are described below. Some data is transmitted through DuyApp servers and some by the device connecting directly to the relevant service.
- Server and database hosting service providers: Account, content and application records are kept on this infrastructure for the purpose of hosting the main application server and database.
- Artificial intelligence and content safety service providers: Duyu chat messages and chat history, the area and time zone from which questions are asked, the masked texts of posts shared under a nickname and suitable for use in Duyu, Duyu Fun scenario texts and comments, and a pseudonymized code derived from the account ID are transmitted in order to provide the artificial intelligence features. This code is derived from the account ID of the user making the Duyu request and is used to detect abuse. The raw account ID is not transmitted; the code is treated as pseudonymized personal data. The texts entered by the user may also contain personal information.
- Media storage, content delivery and website service providers: Photos, the IP addresses of devices viewing the photos, website access logs are processed for media storage, content delivery and hosting the website.
- Email delivery service providers: The email address and verification code are transmitted in order to send verification and account recovery emails.
- Push notification service providers: The notification key and the notification text are transmitted in order to deliver push notifications to the device. The notification delivery service passes notifications to the notification infrastructure of the device's operating system.
- Device operating system and location service providers: Device location is processed to determine the name of the place where the user is located on the post creation screen.
- GIF and visual content service providers: The GIF search text and the IP addresses of devices viewing GIFs are transmitted in order to provide the GIF search and viewing feature.
- Map service providers: The IP address of the device and request information relating to the displayed map area are processed in order to display the map.
The artificial intelligence service provider processes the customer data transmitted to it as a data processor on behalf of DuyApp; the recipient of this service and the use of data are stated in the Duyu data transfer statement. The storage, content delivery and site security provider is a data processor for the services it provides on behalf of DuyApp. The GIF content provider is also an independent data controller for the personal data processing within the scope of its own services.
The recipient groups are stated above by type of service. To request information about the third parties to whom your data is transferred, you may use the methods in the Rights and requests section.
For regular transfers abroad, an adequacy decision or appropriate safeguards are required under Article 9 of the Law. Where standard contracts are used, the prescribed text and the obligations to notify the Authority apply. Where there is no adequacy or appropriate safeguard, the exceptions provided only for incidental transfers do not form a general basis for continuous API and cloud service use. Reading this notice or accepting the Terms of Service does not replace a transfer safeguard.
Retention and deletion
The minimum records documenting deletion, destruction and anonymization operations are kept for at least 3 years from the date of the operation. These records do not contain copies of the contents of deleted posts, comments or messages. These records are kept in order to fulfil the obligation to document destruction operations (Art. 5/2-ç). They are limited to documenting the date, scope, method and result of the operation.
When the reasons requiring the processing of personal data cease to exist, the data is deleted, destroyed or anonymized. Retention periods apply separately to each processing activity.
Deleting an account does not remove a statutory retention obligation that must be fulfilled. Records that must be kept for asserting or defending a legal claim are also kept only for that purpose and for the necessary period.
How an account deletion request is submitted in the application or by email, the timing of the deletion, the data deleted and the records kept after the account is closed are described on the Delete Account page. For personal data requests under the Law, the Rights and requests section of this notice applies.
Age limit
DuyApp is only for persons aged 18 and over. The accounts of users found to be under 18 are closed and their personal data is deleted. Records that must be kept by law are kept only to the extent and for the period of the relevant obligation.
Rights and requests
Under Article 11 of the Law, everyone has the following rights with respect to personal data concerning them:
- To learn whether their personal data is processed; to request information if it has been processed; to learn the purpose of processing and whether the data is used in accordance with that purpose.
- To know the third parties to whom the data is transferred within Türkiye or abroad.
- To request the correction of incomplete or inaccurate data, to request its deletion or destruction within the conditions of Article 7 of the Law, and to request that these operations be notified to the third parties to whom the data has been transferred.
- To object to a result against them arising solely from analysis carried out by automated systems, and to request compensation for damage suffered due to unlawful processing.
Applications may be made in Turkish, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller:
- By sending an email to destek@duyapp.com from the email address previously notified to DuyApp and registered in the system.
- By sending an application signed with a secure electronic signature or mobile signature to destek@duyapp.com.
- By submitting a written application to the postal address in the Data controller section.
The application must include the first name and surname; for written applications, the signature; the T.C. identity number; for foreigners, nationality, passport number or identity number if any; the residential or workplace address for notification purposes; if any, the email address, telephone number and fax number for notification purposes; and the subject of the request. Information and documents supporting the request may be attached to the application.
Information necessary to verify that the application belongs to the person concerned may be requested. Not having a DuyApp account does not prevent the exercise of rights concerning data processed about the person as a visitor or applicant.
Applications are concluded free of charge as soon as possible and within 30 days at the latest, depending on the nature of the request. If the operation requires a separate cost, a fee may be charged according to the tariff set by the Board. If the application arose from the data controller's error, the fee charged is refunded.
If the application is rejected, the response given is found insufficient or no response is given in time, a complaint may be lodged with the Personal Data Protection Board within 30 days from learning of the response and in any case within 60 days from the date of the application.
Changes
This notice is updated according to changes in personal data processing activities. When the purpose of processing changes, the persons concerned are separately informed before data processing for the new purpose begins. An update does not, on its own, create permission for a new processing activity or transfer.