Home / Legal / Privacy & KVKK

Privacy and KVKK Disclosure Notice

A draft of which personal data we plan to process, for what purpose and on which legal ground. With sections on transfers, retention and rights. KVKK is Turkish Personal Data Protection Law No. 6698.

last updated: draft

DRAFT — not reviewed by legal counsel, not in force.

The legal entity that will act as data controller has not been incorporated yet; the product is in Phase 0 and some of the processing activities described here have not started. Fields in square brackets are placeholders left deliberately empty. This notice is drafted under the law of the Republic of Türkiye — primarily KVKK (Turkish Personal Data Protection Law No. 6698) — and the English version is a convenience translation; where the two differ, the Turkish text governs.

1. Data controller

Data controller: [legal name], address [address], MERSİS [MERSİS] (Turkish central trade registry number), KEP [KEP address] (registered electronic mail address under Turkish law). Contact: merhaba@kaldera.ai. Company details will be published on the Contact page and in this text at the same time, once incorporation is complete. Registration with VERBİS (the Turkish registry of data controllers) will be made when the obligation arises.

2. Categories of personal data processed

  • Identity and contact: name, email address, preferred language; for corporate customers, details of the authorised contact.
  • Account and customer transaction: organisation name, role and permission data, API key metadata (a digest, not the key itself), session records.
  • Usage data: workloads started, time and resource quantity used, region preference, metering and health check records.
  • Payment and finance: invoice details, transaction amount and status, references returned by the payment provider. Card numbers are not stored on Kaldera systems.
  • Technical and transaction security: IP address, browser and device information, server logs, error logs.
  • Host side: for people joining as hosts, the outcome of identity verification (KYC) and a payout account reference; KYC documents are held at the payment service provider.

Processing special categories of personal data is not intended. For the data a User uploads into their own workload, Kaldera is as a rule a data processor; it applies no inspection to the content of that data.

3. Purposes of processing and legal grounds (KVKK Art. 5)

The table below maps each data category to its purpose and the legal ground it rests on. Article references are to KVKK (Turkish Personal Data Protection Law No. 6698); the GDPR column gives the equivalent ground.

Data categoryPurposeKVKK legal groundGDPR equivalent
Identity, contact, accountSetting up the account and delivering the serviceArt. 5/2-c — conclusion and performance of a contractArt. 6/1-b
Usage and meteringPer-second billing, budget cap, applying the guaranteeArt. 5/2-c — performance of a contractArt. 6/1-b
Payment and financeCollection, invoicing, keeping financial recordsArt. 5/2-a and Art. 5/2-ç — expressly provided by law and legal obligationArt. 6/1-c
Technical and security logsDetecting abuse, system security, fixing faultsArt. 5/2-f — legitimate interestArt. 6/1-f
Host KYC referencePayment legislation and identity verification obligationsArt. 5/2-a — expressly provided by lawArt. 6/1-c
Communication preferencesProduct announcements and informational messagesArt. 5/1 — explicit consentArt. 6/1-a

The only processing that rests on explicit consent is marketing messages; consent can be withdrawn at any time and withdrawing it does not affect use of the service.

4. Transfers: domestic, cross-border and sub-processors

Personal data is shared with a limited number of service providers so that the service can be delivered. The list below is by category; because the product is in Phase 0, some of these are still planned and will be published here by name once settled.

  • Hosting and infrastructure: the data centre where the control plane runs. Target: hosting inside the European Union.
  • Compute capacity providers: the providers on which the workload actually runs. When region pinning is selected, capacity is served only from the selected country.
  • Payment service provider: collection, host payouts and KYC.
  • Email delivery: transactional notifications.
  • Error and log management: collecting and storing system logs.
  • Competent public authorities: upon a request arising from legislation, limited to the basis and scope of that request.

Where data is transferred abroad, the transfer rests on the KVKK provisions governing transfers (adequacy decision, appropriate safeguards or the statutory exceptions) and, for GDPR purposes, on standard contractual clauses. Keeping identity and session data in our own database rather than in a third-party identity service is an architectural choice.

5. Retention periods

  • Account and contact data: for as long as the account is open; after closure, for a reasonable export window.
  • Usage and metering records: for the same period as financial records, to the extent they underpin an invoice.
  • Financial records and invoices: 10 years (obligations on the retention of commercial books and documents under Turkish law; the minimum periods in tax legislation are reserved).
  • Server and security logs: for the limited period necessary for security purposes.
  • Workload content and persistent storage: until the User deletes it; on account closure, deleted at the end of the announced period.
  • Communication records based on explicit consent: until consent is withdrawn.

At the end of a period, data is deleted, destroyed or anonymised. Exact periods will be updated in this text when the retention and destruction policy is published.

6. Data security measures

  • Encryption in transit and at rest; encryption of secrets at the application layer.
  • Customer secrets are not written to a host disk in plaintext.
  • Role-based authorisation, least privilege, separate authentication for the admin interface and multi-factor sign-in.
  • Masking of personal data in logs and events; tamper-evident recording of administrative actions.
  • Signed container images and rejection of unsigned images.
  • Server-side enforcement of region pinning; an interface filter is not treated as a security boundary.

In the event of a data breach, notification is made to the Kişisel Verileri Koruma Kurulu (the Turkish Personal Data Protection Board) and to the affected individuals, within the time and in the manner required by law.

7. Rights of the data subject (KVKK Art. 11)

Every data subject has the right to: learn whether their personal data is processed; request information if it has been; learn the purpose of processing and whether the data is used in line with that purpose; know the third parties, domestic or abroad, to whom the data has been transferred; request correction if the data is incomplete or inaccurate; request erasure or destruction; request that correction and erasure be notified to the third parties the data was transferred to; object to a result reached against them through analysis carried out solely by automated systems; and claim compensation for damage arising from unlawful processing.

8. How to apply

Applications may be made in writing, or through registered electronic mail (KEP), secure electronic signature, or an email address already registered in the system, in accordance with the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller. An application should include the applicant's name, contact details, the subject of the request and information that verifies their identity. Requests are concluded within the statutory maximum of 30 days; if the process requires an additional cost, the fee set in the Board's tariff may be charged. If an application is refused or not answered in time, the right to complain to the Kişisel Verileri Koruma Kurulu (the Turkish Personal Data Protection Board) is reserved.

9. Rights under the GDPR

For data subjects located in the European Union, the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing apply, together with the right to withdraw explicit consent. A data subject may also lodge a complaint with the supervisory authority in their own country. Requests can be sent to the contact address above.

10. Automated decisions and profiling

No solely automated decision-making or profiling producing legal effects on individuals is carried out. The marketplace scorecard is a performance measurement of machines and providers, not of people.

11. Cookies

The cookies used on this site and in the console, and the preferences stored in the browser, are explained in a separate text: Cookie Notice.

12. Changes

This text will be updated as the product phases advance and as sub-processors are settled. Material changes are notified to the account email address and inside the console.

Legal

Data should stay wherever it is meant to stay.

For us sovereignty is not a marketing word but a rule enforced server-side. Write to us about the clause you find missing in this draft.

Draft text; not in force.