KVKK Notice (Türkiye)
Last updated: May 2026.
Notice provided under Article 10 of the Personal Data Protection Law No. 6698 ("KVKK"). This page explains who controls your personal data, what we collect, why, how long we keep it, and how to exercise your rights.
Data controller (Veri Sorumlusu)
BRNVLY YAZILIM TİCARET ANONİM ŞİRKETİ (operating under the brand "Clastrum"). Registered office: Hasanpaşa Mah. Nabizade Sk. B Blok No: 82, Interior No: 1, Kadıköy / İstanbul. MERSİS: 0187176676500001 · Istanbul Trade Registry No: 1137479 · Tax No: 1871766765 (Kadıköy Tax Office). Sole board member with sole signature authority: Baran Velayi.
Data Protection Officer (Veri Sorumlusu İrtibat Kişisi)
dpo@clastrum.com — for all KVKK rights requests, complaints, and data-protection correspondence. We respond within 30 days as required by Article 13.
Categories of personal data
Identity (full name, role), contact (email, telephone), business (company name, problem description, data description, project timeline, budget range), transactional (booking metadata, IP address and user-agent in server logs for up to 30 days), and — only where you create an account — authentication metadata (last sign-in, IP, browser).
Purposes of processing
Responding to your inquiry, preparing a discovery call, executing engagements under a signed Statement of Work, fulfilling our legal and tax obligations (including invoicing and bookkeeping), and security/abuse prevention.
Legal grounds (Article 5)
Art. 5/2(c) — necessity for the establishment or performance of a contract you are a party to. Art. 5/2(ç) — fulfilment of a legal obligation to which we are subject (TTK, VUK, VAT law). Art. 5/2(f) — legitimate interest, where the processing does not override your fundamental rights (e.g. server-log abuse prevention). Art. 5/1 — your explicit consent, sought separately for marketing-adjacent communications.
Sub-processors and cross-border transfers
Supabase (managed Postgres, EU region); Resend (transactional email, US); Vercel (hosting, US/EU). Transfers outside Türkiye are protected by standard contractual clauses or equivalent safeguards under Articles 9/2 and 9/6 KVKK.
Retention
Inquiries: 24 months from last contact, then deleted or anonymised. Server logs: 30 days. Statutory records (invoices, contracts, tax-relevant data): retained for the periods required by Turkish Commercial Code and Tax Procedure Law (typically 10 years).
Your rights (Article 11)
(a) Learn whether your personal data is processed; (b) request information about how it is processed; (c) learn the purpose and whether data is used consistent with that purpose; (ç) learn third parties to whom data is transferred domestically and abroad; (d) request correction of incomplete or incorrect data; (e) request deletion or destruction under Article 7; (f) request notification of corrections/deletions to third parties; (g) object to outcomes arising from automated analysis; (ğ) claim damages from unlawful processing. To exercise any of these: email dpo@clastrum.com. You also have the right to complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — www.kvkk.gov.tr).
How to submit a request
Send a signed written request — in person, by registered mail, by notarised channel, or via secure electronic signature — to the registered address above, or by email to dpo@clastrum.com. Please include your full name, TC kimlik or passport number, the right you are exercising, and a clear description of your request, per the Communiqué on Procedures and Principles for Application to Data Controllers.