Privacy Policy and KVKK Notice

Last updated: August 12, 2026 · Version 2.1

As part of our duty to inform you under Turkish Personal Data Protection Law no. 6698 ("KVKK"), this document explains for what purposes your personal data is processed when you use the Parlat App, who it is shared with, how long it is retained and what your rights are. The data controller is DKPEAK; you can reach us with any request at [email protected].

1. Categories of Personal Data Processed

Identity and contact data: full name, email address, phone number (if you enter one), and the user id generated by the system.

Account and security data: sign-in method, your user id at that provider, session records (creation, last use and expiry times of the session, and the reason it was revoked), language preference, credit balance. Your session refresh key is not stored in the clear; only an irreversible hash of it is kept.

Device data: the country code read from your device's Region setting, and the platform your account was created on (iOS/Android). These two values are read from device settings without any permission prompt and are recorded only during sign-in. Your app version and build number are evaluated only at the moment of the forced-update check and are not stored.

Worker profile data: address, location coordinates, the free-text description of yourself, gender, date of birth, experience range, the service types you offer, profile approval status, average rating and number of completed jobs.

Employer profile data: address, location coordinates, home size, number of bathrooms, whether there is a child, an elderly person or a pet in the home, additional service requests and your free-text notes.

Content data: the listings and listing photos you create, your application notes, message content, review ratings and comments, report records and block records.

Transaction data: your credit movements, spending and earning records, the transaction number generated by the store for a purchase, and your visibility package records.

Notification data: your device's push notification subscription id and your notification preferences.

Support data: the subject and content of your support request and the date it was sent.

Moderation data: any ban applied to your account with its reason and date, and the approval status of your Worker profile.

2. Data We Do Not Collect

We do not store your IP address in our database. An IP address is held only transiently in memory (for at most one hour) during rate limiting intended to prevent abuse.

We do not collect browser/device identifiers (user-agent) or advertising identifiers (IDFA/AAID), and we do not track you across other companies' apps or websites. The App contains no advertising network and no crash-reporting tool (such as Sentry). Its only measurement tool is Meta's SDK, which reports the limited set of app events described in section 5 so that we can measure our own advertising campaigns.

We have no access to your payment card details, billing information, payment amount or store receipt; payment is carried out entirely by Apple or Google.

We do not access your contacts, calendar, microphone or your photo library as a whole. Only the images you personally select in the picker are sent to us.

We do not track your location in the background. Location is read only while the app is open and only if you have granted permission.

3. How Personal Data Is Collected

Most of the data is provided directly by you through the App: profile information, listings, messages, reviews, applications and support requests.

Some of it is taken automatically from the Google, Apple or Facebook account you sign in with: your email address, your name and (for Google and Facebook) your profile photo.

Some of it is generated automatically while the App runs: session records, credit movements, notification records and your device's region setting.

Location data is read only where you have granted device permission and only while the App is open.

All of this processing is carried out by wholly or partly automated means, relying on the conditions set out in article 5 of the KVKK.

4. Purposes of Processing and Legal Grounds

Creating your account, authentication, publishing profiles and listings, running the application and messaging flows, operating the credit system and sending the notifications you asked for: necessary for the establishment and performance of a contract (KVKK art. 5/2-c).

Preventing abuse, fraud and deception, keeping accounts secure, rate limiting, reviewing rule-violation reports, approving Worker profiles and protecting the quality of the platform: our legitimate interests (KVKK art. 5/2-f).

Retaining message, review, transaction and report records that may serve as evidence in a dispute: establishment, exercise or protection of a right (KVKK art. 5/2-e).

Compliance with tax, commercial and consumer legislation and with requests from competent authorities: fulfilment of our legal obligations (KVKK art. 5/2-ç).

Measuring and improving the advertising campaigns we run for Parlat — knowing whether a campaign led to an installation, a completed registration, an application to a listing, a published listing, a first message or a credit purchase: our legitimate interests (KVKK art. 5/2-f). These events are not linked to your identity, no advertising identifier is used, and on iOS the results reach us in aggregate through Apple's SKAdNetwork.

Reading your device location and sending marketing or campaign notifications: your explicit consent (KVKK art. 5/1). You can withdraw these consents at any time from your device settings or from the notification preferences in the App; withdrawal does not affect the lawfulness of processing carried out beforehand.

5. Who We Share Your Personal Data With

Other users: because the App is a marketplace, your profile information, listing details and message content are made available to the other party. Exactly what is visible is listed in section 7.

Google LLC: sign-in with Google (verifying your email, name, profile photo and user id) and the address suggestion service. The text you type into an address field is sent directly from your device to the Google Places service in order to build the suggestion list. Your Google account profile photo is served from Google's servers.

Apple Inc.: sign in with Apple (your user id and email address; if you use "Hide My Email", the private relay address) and in-app purchases made through the App Store.

Meta Platforms, Inc.: sign in with Facebook, and measurement of our own advertising campaigns. If you sign in with Facebook, Meta passes us your user id, name, email address and profile photo; your profile photo is served from Meta's servers. Separately, and for every user whether or not Facebook sign-in is used, Meta's software development kit (SDK) reports a limited set of app events to Meta: installing the App, opening it, completing registration, applying to a listing, publishing a listing, sending the first message in a conversation, and purchasing credits (with the amount and currency of that purchase). For the application and the listing we also report how many credits were spent. Nothing else travels with these events: no listing or user identifier, no service category, and — for the first message — no content, no recipient and nothing else about the conversation. We use them only to measure and improve the advertising campaigns we run for Parlat. The SDK does not collect your device's advertising identifier (IDFA/AAID), we do not track you across other apps or websites, and we send Meta no matching data such as your email address or telephone number. On iOS, attribution is performed through Apple's SKAdNetwork, which reports results in aggregate rather than at the level of an individual user.

Our push notification delivery provider: your device's notification subscription id and the title and body of the notification. Your message content is not sent to the notification provider; message notifications say only "You have a new message". However, notifications such as appointment requests, rejections and cancellations do include the other party's name in the notification text.

Our in-app purchase infrastructure provider: your user id, the purchased product code and the store transaction number.

Our email delivery provider: only when you send a support request; your name, email address, phone number, user id, account creation date and the content of your message.

Our server, database and file storage (hosting) provider: hosting of the App's data and storage of the images you upload.

Our app update infrastructure provider: the App checks for updates on every launch, during which your device's IP address, platform and app version are sent to the provider.

Only the data necessary to provide the service is shared with our service providers, and those providers may not use your data for their own purposes. You can request the current list of the service providers your personal data is transferred to at [email protected].

Competent authorities: we may share data with judicial and administrative authorities to the extent required by law, in order to comply with a legal obligation, protect our rights or prevent an offence.

6. Transfers Abroad

Some of the service providers listed above are established abroad or have servers abroad. Your personal data is therefore transferred abroad to the extent necessary to provide the service.

Transfers abroad concern Google, Apple and Meta and the categories of service provider listed in section 5. You can request the current list of the providers involved at [email protected].

The profile and listing photos you upload are stored in our provider's storage infrastructure in the Amsterdam (Netherlands) region.

These transfers are carried out under article 9 of the KVKK, on the basis that they are necessary for the performance of a contract and/or with your explicit consent, together with the appropriate safeguards required by law.

7. What Other Users Can See

When your Worker profile is viewed: your full name, profile photo, email address, phone number, address and location, your self-description, gender, date of birth, experience, the services you offer, your rating and the reviews you have received are visible.

When your Employer profile is viewed: your full name, profile photo, email address, phone number, address and location, home size, number of bathrooms, whether there is a child, an elderly person or a pet in the home, your additional service requests and your notes are visible.

In your listings: the listing address and location, title, description, date and time information, price and the photos you uploaded are visible to all users.

Reviews you leave are published on the profile of the user you reviewed, together with your name and profile photo.

For that reason we recommend entering only information you are comfortable sharing in profile and listing fields. Your Worker profile is not visible to other users until it has been approved by an administrator.

8. Accessibility of Photos

The profile photos and listing images you upload are stored in a cloud storage service with publicly reachable link addresses so that the app stays fast. The link addresses are generated randomly so they cannot be guessed and are not listed anywhere; however, a person who knows the link can open the image without signing in.

For that reason your photos should not contain sensitive information such as identity documents, address signs or vehicle licence plates, or images of people who have not consented.

When you change your profile photo the old image is deleted from storage. When you delete a listing its images are deleted as well. When your account is permanently closed these images are deleted from storage.

9. Privacy of Messages

Your messages are stored on our servers and are not end-to-end encrypted.

Our authorised personnel may access message content in order to review rule-violation reports, combat fraud and abuse, protect user safety and respond to requests from competent authorities. Such access is limited to these purposes and to a small number of authorised people.

We do not use the content of your messages for marketing, profiling or advertising, and we do not sell your messages to third parties. There is a single exception, and it carries no content: when a conversation receives its first message we report to Meta that this happened, as one of the advertising measurement events described in section 5. Neither the message, nor who it was sent to, nor which conversation it belonged to is included — only that a first contact took place.

10. Location Data

Location permission is entirely optional and can be skipped with the "Not now" option on the permission screen. If you do not grant it you can still use the App; only sorting by proximity will not work, and the list will be sorted by date instead.

Location is read only while the App is open and at approximate accuracy; there is no background location tracking.

The location that is read is used to show you nearby listings and users and to calculate distance. The address and coordinates you choose when creating a profile or listing are stored as part of that record.

You can withdraw location permission at any time from your device settings.

11. Notifications and Your Preferences

Notification permission is optional. You can turn notifications off entirely or manage them by category (messages, applications and appointments, reviews, campaigns). These settings are under Profile > Notification Preferences.

When you turn notifications off, your device's notification subscription id is deleted from our records.

Information that is essential to the operation of the App (for example account security or a maintenance announcement) may be shown inside the App regardless of your notification preferences.

12. Retention Periods and Account Deletion

Your personal data is retained for as long as the purpose of processing requires, subject to the limitation and retention periods prescribed by applicable legislation.

Session records are kept for at most 30 days; rate-limiting data for at most 1 hour (in memory only); conversations for approximately 1 month from creation; daily listings stay published until the following day and live-in listings for 14 days.

When you delete your account: your profile and listings immediately become invisible, all your sessions are ended, and a 30-day restore window begins. No data is destroyed during that window; you can restore your account by signing in.

At the end of the 30 days your account is permanently anonymised. At that point your full name, email address, phone number, profile photo, sign-in provider id, country and platform information and credit balance are erased or made unidentifiable; your address, location, description, date of birth, gender and listing details are cleared; and the images you uploaded are deleted from storage. Your session records, notifications and block records are deleted entirely.

Data that continues to be retained after anonymisation, and why: messages and reviews (these are records to which the other party is also a party — deleting them would destroy the other user's history and corrupt their average rating), credit movements (financial records and potential disputes) and report records (moderation history). These records are kept stripped of information that directly identifies you. The date of your deletion request and the date of anonymisation are retained as an audit trail.

Anonymisation cannot be undone. If you sign in afterwards with the same Google/Apple/Facebook account, a new account is created.

13. Data Security

Your data is protected in transit by an encrypted connection (TLS).

Session refresh keys are not stored in the clear; only irreversible hashes of them are kept. Access keys are short-lived and are rotated regularly. If a session key is detected being reused, all of that user's sessions are ended as a security measure.

Passwords for administrator accounts are stored using a strong hashing algorithm; app users have no password at all and sign in through Google, Apple or Facebook.

Access to the administration panel is restricted by role-based authorisation. Rate limiting is applied to endpoints, all incoming data is validated, and the sessions of banned accounts are ended immediately.

Despite all these measures, we remind you that no system is completely secure. If you notice a vulnerability, please report it to [email protected].

14. Automated Decision-Making

There is no decision made solely by automated means that produces legal effects concerning you or significantly affects you.

Decisions to approve or reject Worker profiles, and decisions to ban an account, are made after review by an authorised person. You can appeal such decisions at [email protected].

15. Your Rights (KVKK art. 11)

Under article 11 of the KVKK you have the right to: learn whether your personal data is being processed; request information if it has been processed; learn the purpose of processing and whether the data is used in line with that purpose; know the third parties to whom it has been transferred domestically or abroad; request correction if it has been processed incompletely or incorrectly; request erasure or destruction within the conditions set out in the KVKK; request that correction and erasure operations be notified to the third parties to whom the data was transferred; object to a result against you arising from analysis carried out solely by automated systems; and claim compensation if you suffer loss because of unlawful processing.

You can exercise some of these rights directly in the App: you can edit your profile information, change your notification preferences, manage the users you have blocked, delete your listings and conversations, sign out of all devices and request deletion of your account.

If you request a copy of your data, that request cannot currently be fulfilled automatically from within the App; it is prepared manually upon an application sent to [email protected].

16. How to Apply

You can send requests under the KVKK to [email protected]. Please state your request clearly in your application.

We may ask for additional information to verify your identity so that we can be sure the application is yours.

Your requests are concluded free of charge as soon as possible and in any event within 30 days, depending on their nature. If the operation entails an additional cost, the fee in the tariff set by the Personal Data Protection Board may be charged.

If your application is rejected or you find our response insufficient, you may complain to the Personal Data Protection Board within 30 days of learning of the response and in any event within 60 days of the date of your application.

17. Children

The App is not directed at people under 18 and is closed to their use. We do not knowingly collect personal data from anyone under 18.

If we detect, or are notified, that a person under 18 has created an account, we close the account and erase the relevant data. You can report such a situation to us at [email protected].

18. Data Breach Notification

If we determine that your personal data has been unlawfully obtained by others, we will notify the Personal Data Protection Board and the affected data subjects as soon as possible, in accordance with article 12 of the KVKK.

19. Updates and Contact

We may update this document in line with changes to our services or to legislation. When we do, we change the "Last updated" date and the version number, and for significant changes we also notify you inside the App.

The Turkish version of this document prevails; the English text is provided for information only.

Data controller: DKPEAK. For any question, request or application: [email protected]