KVKK Aydınlatma Metni
Önemli: Bu metin PROOFG ürün mimarisine göre hazırlanmış teknik bir aydınlatma taslağıdır. Ticari kullanıma geçmeden önce veri sorumlusunun tam ticari unvanı, adresi, KEP/e-posta bilgileri ve varsa VERBİS bilgileri hukuk danışmanı tarafından tamamlanmalı ve doğrulanmalıdır.
1. Veri sorumlusu ve iletişim
PROOFG hizmetinin veri sorumlusu, hizmeti hukuken işleten gerçek veya tüzel kişidir. Gizlilik ve veri koruma başvuruları için mevcut iletişim kanalı: privacy.proofg@gmail.com.
2. İşlenen veri kategorileri
Hesap ve kimlik bilgileri; e-posta, telefon, ülke/şehir; işletme başvuru ve ekip bilgileri; cihaz/iş emri bilgileri; kullanıcı tarafından yüklenen fotoğraf, video, belge ve notlar; kayıt bütünlüğü için SHA-256 ve PROOFG Mührü metadata'sı; güvenlik, oturum, audit, destek ve paylaşım kayıtları işlenebilir.
3. İşleme amaçları
Temel hizmet notu: Fotoğraf, video, belge ve bunlara bağlı bütünlük/audit verilerinin kayıt, karşılaştırma, doğrulama, PDF/rapor ve uyuşmazlıkta hakların korunması amacıyla işlenmesi PROOFG hizmetinin çekirdek işlevidir. Bu gerekli işleme, opsiyonel pazarlama açık rızasına bağlanmaz.
- Hesap oluşturma, kimlik doğrulama ve erişim güvenliği.
- Bireysel kayıt, İşletme iş emri, Önce/Sonra, Compare, PDF/rapor ve doğrulama bağlantısı hizmetlerini sunma.
- Dolandırıcılık, kötüye kullanım ve güvenlik olaylarını önleme.
- Destek taleplerini ve işletme onaylarını yönetme.
- Kayıt bütünlüğünü, audit izini ve uyuşmazlık halinde hukuki hakların tesisi, kullanılması veya korunması için gerekli delil zincirini koruma.
- Yasal yükümlülükleri yerine getirme ve yetkili makam taleplerine cevap verme.
4. Hukuki sebepler
İşleme faaliyeti, somut işleme amacına göre 6698 sayılı Kanun'daki sözleşmenin kurulması/ifası, hukuki yükümlülük, bir hakkın tesisi-kullanılması-korunması, meşru menfaat ve gerekli olduğu özel durumlarda açık rıza gibi uygun hukuki sebeplere dayanır. Bir işleme faaliyeti başka bir hukuki sebebe dayanabiliyorsa kullanıcıdan sırf hizmet şartı olarak açık rıza alınmaz.
5. Aktarım ve hizmet sağlayıcılar
Barındırma, kimlik doğrulama, güvenlik ve altyapı için Supabase ve Vercel gibi hizmet sağlayıcılardan yararlanılabilir. Yurt dışına veri aktarımı söz konusu olduğunda yürürlükteki KVKK aktarım hükümlerine uygun mekanizma kurulmadan aktarım yapılmamalıdır.
6. Saklama
Veriler amaç için gerekli süre ve uygulanabilir yasal saklama süreleri boyunca tutulur. Kanıt kayıtlarında bütünlük, uyuşmazlık ve hukuki hakların korunması için daha uzun saklama gerekebilir. Saklama politikası veri kategorisi bazında belirlenecektir.
7. Yönetici erişimi ve kanıt kasası
PROOFG yöneticileri kullanıcı içeriklerine genel amaçlı serbest erişim sağlamaz. Kanıt içeriği yalnız yetkili ve kayıtlı amaçlarla, rol bazlı yetki, erişim gerekçesi, kısa süreli erişim bağlantısı ve audit kaydı altında incelenebilir.
8. İlgili kişi hakları
KVKK'nın 11. maddesi kapsamındaki haklarınız için veri sorumlusuna başvurabilirsiniz. Kimlik doğrulaması ve başvurunun niteliğine göre ek bilgi istenebilir.
Privacy Notice (Türkiye / KVKK)
Important: This is a technical privacy-notice draft aligned with the the current PROOFG product architecture. Before commercial launch, the full legal identity, address, official contact details and any required registry information of the data controller must be completed and reviewed by Turkish counsel.
1. Data controller and contact
The data controller is the legal person or individual operating the PROOFG service. Current privacy contact: privacy.proofg@gmail.com.
2. Categories of data
Account identity data, e-mail, phone, location, business application and team data, device/work-order data, photos, videos, documents and notes uploaded by users, SHA-256 and PROOFG Seal metadata, security/session/audit/support and sharing records may be processed.
3. Purposes
- Account creation, identity verification and access security.
- Providing Personal records, Business work orders, Before/After, Compare, PDF/report and verification-link features.
- Preventing fraud, abuse and security incidents.
- Managing support and Business review.
- Preserving integrity and audit evidence when necessary to establish, exercise or protect legal rights.
- Meeting legal obligations and valid authority requests.
4. Legal grounds
Depending on the specific processing purpose, processing may rely on performance of a contract, legal obligations, establishment/exercise/protection of a right, legitimate interests, or explicit consent where legally required. Consent should not be made a condition of service where another valid legal basis applies.
5. Transfers and service providers
Supabase, Vercel and other infrastructure providers may be used. Cross-border transfers must use a lawful transfer mechanism required by applicable Turkish data-protection law.
6. Retention
Data is retained only as long as necessary for the purpose and applicable legal retention periods. Evidence records may require longer retention for integrity, disputes or protection of legal rights.
7. Administrator access and Evidence Vault
Administrators do not receive unrestricted general access to user content. Evidence content is reviewed only by authorized roles for a recorded purpose, using short-lived access links and an audit trail.
8. Data-subject rights
You may exercise the rights available under Article 11 of the Turkish Personal Data Protection Law by contacting the data controller.
Notice d’information sur les données personnelles (KVKK)
Important : ce document est un projet technique de notice d’information adapté à l’architecture produit actuelle de PROOFG. Avant tout lancement commercial, l’identité juridique complète, l’adresse et les coordonnées officielles du responsable du traitement doivent être complétées et vérifiées par un conseil juridique en Turquie.
1. Responsable du traitement et contact
Le responsable du traitement est la personne physique ou morale qui exploite juridiquement le service PROOFG. Contact actuel : privacy.proofg@gmail.com.
2. Catégories de données
Données de compte et d’identité, e-mail, téléphone, localisation, données de demande Entreprise et d’équipe, données d’appareil/ordre de travail, photos, vidéos, documents et notes téléversés, métadonnées SHA-256 et Sceau PROOFG, ainsi que journaux de sécurité, session, audit, assistance et partage.
3. Finalités
- Création de compte, vérification d’identité et sécurité d’accès.
- Fourniture des fonctions Particulier, Entreprise, Avant/Après, Comparaison, PDF/rapport et liens de vérification.
- Prévention de la fraude, des abus et des incidents de sécurité.
- Gestion de l’assistance et des validations Entreprise.
- Conservation de l’intégrité et de la piste d’audit lorsque cela est nécessaire à la constatation, l’exercice ou la défense d’un droit.
- Respect des obligations légales et des demandes valides des autorités.
4. Bases juridiques
Selon la finalité, le traitement peut reposer sur l’exécution d’un contrat, une obligation légale, la constatation/exercice/défense d’un droit, l’intérêt légitime ou le consentement explicite lorsqu’il est juridiquement requis. Le consentement ne doit pas être imposé comme condition du service lorsqu’une autre base légale s’applique.
5. Transferts et prestataires
PROOFG peut utiliser Supabase, Vercel et d’autres prestataires d’infrastructure. Tout transfert international doit reposer sur un mécanisme conforme au droit turc applicable.
6. Conservation
Les données sont conservées pendant la durée nécessaire et les délais légaux applicables. Les preuves peuvent être conservées plus longtemps pour l’intégrité, les litiges ou la défense de droits.
7. Accès administrateur et coffre de preuves
Les administrateurs ne disposent pas d’un accès général illimité au contenu. L’accès aux preuves est réservé aux rôles autorisés, pour une finalité enregistrée, via des liens temporaires et une piste d’audit.
8. Droits des personnes
Vous pouvez exercer les droits prévus par l’article 11 de la loi turque sur la protection des données en contactant le responsable du traitement.
