Home / Legal / Privacy & KVKK
A draft of which personal data we plan to process, for what purpose and on which legal ground. With sections on transfers, retention and rights. KVKK is Turkish Personal Data Protection Law No. 6698.
last updated: draft
The legal entity that will act as data controller has not been incorporated yet; the product is in Phase 0 and some of the processing activities described here have not started. Fields in square brackets are placeholders left deliberately empty. This notice is drafted under the law of the Republic of Türkiye — primarily KVKK (Turkish Personal Data Protection Law No. 6698) — and the English version is a convenience translation; where the two differ, the Turkish text governs.
Data controller: [legal name], address [address], MERSİS [MERSİS] (Turkish central trade registry number), KEP [KEP address] (registered electronic mail address under Turkish law). Contact: merhaba@kaldera.ai. Company details will be published on the Contact page and in this text at the same time, once incorporation is complete. Registration with VERBİS (the Turkish registry of data controllers) will be made when the obligation arises.
Processing special categories of personal data is not intended. For the data a User uploads into their own workload, Kaldera is as a rule a data processor; it applies no inspection to the content of that data.
The table below maps each data category to its purpose and the legal ground it rests on. Article references are to KVKK (Turkish Personal Data Protection Law No. 6698); the GDPR column gives the equivalent ground.
| Data category | Purpose | KVKK legal ground | GDPR equivalent |
|---|---|---|---|
| Identity, contact, account | Setting up the account and delivering the service | Art. 5/2-c — conclusion and performance of a contract | Art. 6/1-b |
| Usage and metering | Per-second billing, budget cap, applying the guarantee | Art. 5/2-c — performance of a contract | Art. 6/1-b |
| Payment and finance | Collection, invoicing, keeping financial records | Art. 5/2-a and Art. 5/2-ç — expressly provided by law and legal obligation | Art. 6/1-c |
| Technical and security logs | Detecting abuse, system security, fixing faults | Art. 5/2-f — legitimate interest | Art. 6/1-f |
| Host KYC reference | Payment legislation and identity verification obligations | Art. 5/2-a — expressly provided by law | Art. 6/1-c |
| Communication preferences | Product announcements and informational messages | Art. 5/1 — explicit consent | Art. 6/1-a |
The only processing that rests on explicit consent is marketing messages; consent can be withdrawn at any time and withdrawing it does not affect use of the service.
Personal data is shared with a limited number of service providers so that the service can be delivered. The list below is by category; because the product is in Phase 0, some of these are still planned and will be published here by name once settled.
Where data is transferred abroad, the transfer rests on the KVKK provisions governing transfers (adequacy decision, appropriate safeguards or the statutory exceptions) and, for GDPR purposes, on standard contractual clauses. Keeping identity and session data in our own database rather than in a third-party identity service is an architectural choice.
At the end of a period, data is deleted, destroyed or anonymised. Exact periods will be updated in this text when the retention and destruction policy is published.
In the event of a data breach, notification is made to the Kişisel Verileri Koruma Kurulu (the Turkish Personal Data Protection Board) and to the affected individuals, within the time and in the manner required by law.
Every data subject has the right to: learn whether their personal data is processed; request information if it has been; learn the purpose of processing and whether the data is used in line with that purpose; know the third parties, domestic or abroad, to whom the data has been transferred; request correction if the data is incomplete or inaccurate; request erasure or destruction; request that correction and erasure be notified to the third parties the data was transferred to; object to a result reached against them through analysis carried out solely by automated systems; and claim compensation for damage arising from unlawful processing.
Applications may be made in writing, or through registered electronic mail (KEP), secure electronic signature, or an email address already registered in the system, in accordance with the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller. An application should include the applicant's name, contact details, the subject of the request and information that verifies their identity. Requests are concluded within the statutory maximum of 30 days; if the process requires an additional cost, the fee set in the Board's tariff may be charged. If an application is refused or not answered in time, the right to complain to the Kişisel Verileri Koruma Kurulu (the Turkish Personal Data Protection Board) is reserved.
For data subjects located in the European Union, the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing apply, together with the right to withdraw explicit consent. A data subject may also lodge a complaint with the supervisory authority in their own country. Requests can be sent to the contact address above.
No solely automated decision-making or profiling producing legal effects on individuals is carried out. The marketplace scorecard is a performance measurement of machines and providers, not of people.
The cookies used on this site and in the console, and the preferences stored in the browser, are explained in a separate text: Cookie Notice.
This text will be updated as the product phases advance and as sub-processors are settled. Material changes are notified to the account email address and inside the console.
Legal
For us sovereignty is not a marketing word but a rule enforced server-side. Write to us about the clause you find missing in this draft.
Draft text; not in force.