KVKK and GDPR
What we do with your data under KVKK and GDPR
Türkiye's Personal Data Protection Law No. 6698 (KVKK) applies to companies in Türkiye, and the GDPR applies to data of people in the European Union. This page sets out our role under both, how data subjects exercise their rights, the transfer of data to Germany and how AI processing works.
Submit a requestHow to exercise your rights
- 1
Identify the controller
If you are a customer or employee of a company that uses Müşavir, apply directly to that company; it is the controller. If you are a Müşavir subscriber or a site visitor, apply to us.
- 2
Send your request in writing
Use the contact page for requests addressed to us. State the information we need to verify your identity and what your request is about.
- 3
Receive the answer
Under KVKK Article 13, requests are concluded within thirty days at the latest. For GDPR requests the period is one month as a rule.
- 4
Support for the controller
If a request reaches a tenant company, we help it find, correct, export and delete records with platform tools and, where needed, with our team.
Where the AI helps
AI and personal data
AI assistants work by sending records relevant to your question to a model provider. We apply the rules below to that processing.
- Customer data is not used to train AI models; our contract with the model provider says so.
- Only the records needed to answer the question are sent to the model, never the whole database.
- AI may perform internal workflow steps, such as routing a request to the right team; it does not on its own take decisions that produce legal effects or significantly affect a person. Every message, payment or official submission that leaves the company waits for a person's approval.
- Every AI action is logged; record changes made inside the panel can be undone.
Our position
- KVKK (Law No. 6698): We are the processor for data tenants enter, and the controller for our own subscribers and site visitors. Data security obligations (Article 12) apply to us in both roles.
- GDPR (2016/679): For tenants processing data of people in the European Union we act as a processor within the meaning of GDPR Article 28, and we sign a matching data processing agreement on request.
Cross-border transfer
The platform runs in a data center in Germany. Since the Personal Data Protection Board has not issued an adequacy decision for Germany, sending data from Türkiye to these servers is a cross-border transfer under KVKK Article 9; we do not claim that it is exempt because it is in Europe. Accordingly, we are carrying out the process of signing the Board’s standard contracts with recipients and notifying the Authority under Article 9(4)(c). Some subprocessors (such as email, error monitoring and the AI model) may process data outside Türkiye and Germany too; all of them are listed with their locations on the subprocessors page.
Data subject rights
How to apply for the rights under KVKK Article 11 and GDPR Articles 15 to 22:
- If your relationship is with a company that uses Müşavir (as its customer, employee or supplier), apply to that company.
- If your relationship is directly with us, apply in writing through the contact page. Details are in our privacy policy.
- KVKK requests are concluded within thirty days at the latest and free of charge as a rule (Article 13).
Automated decisions and AI
KVKK Article 11(1)(g) grants a right to object to an adverse result produced solely by automated analysis, and GDPR Article 22 provides similar protection. AI assistants on the platform produce suggestions, drafts and answers, and may perform internal workflow steps such as routing a request to the right team. They do not on their own take decisions that produce legal effects or significantly affect a person; every action that leaves the company waits for a person’s approval, and every AI action is logged.
Frequently asked questions
Is storing data in Germany a cross-border transfer?
Yes. Sending personal data from Türkiye to Germany is a cross-border transfer under KVKK Article 9. Accordingly, we are carrying out the process of signing the Board's standard contracts with recipients and notifying the Authority under Article 9(4)(c); the transfer is also addressed in the data processing agreement.
What rights do I have?
Under KVKK Article 11 you can learn whether your data is processed, request information, learn the purpose, know the third parties it is transferred to, request correction and deletion, ask that these actions be notified to third parties, object to an adverse result from solely automated analysis, and claim compensation. The GDPR also grants data portability and restriction of processing.
I am a customer of a company; can I ask Müşavir to delete my data?
Your request should go to the company that is the controller; we process on its behalf. If a request reaches us, we forward it to that company and help it fulfil the request.
Is AI trained on my data?
No. Customer data is not used for model training. The model provider is bound by contract and appears on our subprocessor list.
What do you do in case of a data breach?
We inform the tenant without undue delay and provide the information it needs, as controller, to notify the Board and the people affected. For data where we are the controller, we make the notification ourselves.
Related
Trust Center →
Security, KVKK and GDPR, subprocessors, backups and the compliance roadmap in one place.
Data Processing →
Controller and processor roles, data categories per module and retention.
Subprocessors →
Service providers, their purpose, the data they process and location; 30-day notice.
Privacy Policy →
How Müşavir collects, uses and protects personal data.
Your AI team →
A sales advisor, a bookkeeper, an HR specialist, an operations assistant and a growth advisor, working inside your own data.
Send your data protection question
For a data subject request or questions about KVKK and GDPR, write to us through the contact page.
Submit a request