SECTION 1Identity of the data controller
Your personal data is processed under Personal Data Protection Law No. 6698 (the “Law”) by the data controller identified below.
- Brand
- Pro/Ref
- KVKK application e-mail
- kvkk@proref360.com
SECTION 2Division of roles: controller versus processor
The platform involves two distinct data relationships, with different responsibilities:
- As data controller: For website visitors, those submitting demo/contact forms, authorized contacts of subscribing organizations and platform user accounts, personal data is processed for purposes we determine.
- As data processor: For employee, teacher, administrator, parent and external evaluator data uploaded to the platform by the subscribing organization, the data controller is the organization itself. We process such data solely on the organization's instructions and within the Data Processing Agreement (DPA) between us; we do not use it for our own purposes.
If you are taking part in an evaluation and asking how your data is processed, the privacy notice of your organization and its administrator are the primary point of reference. Requests sent to us are forwarded to the relevant organization.
SECTION 3Categories of personal data processed
- Identity
- First and last name; the authorized contact's name for corporate buyers; national identity/tax number where required for invoicing.
- Contact
- E-mail address, phone number, organization address, billing address.
- Customer transactions
- Subscription plan, order and invoice records, payment status, support requests and correspondence.
- Financial
- Invoice details, payment amount and date, transaction reference returned by the payment institution. Card numbers and CVV data are never received or stored by us.
- Transaction security
- IP address, session and sign-in records, device/browser information, audit log records, failed sign-in attempts.
- Professional experience
- Title within the organization, unit/level and role in the evaluation relationship (manager, peer, subordinate, etc.).
- Evaluation data
- Responses to evaluation forms and open-ended comments (for this data the subscribing organization is the data controller).
- Marketing
- Only where explicit consent has been given: newsletter/promotion preferences and consent records.
Special categories of personal data defined in Article 6 of the Law (health, religion, membership, biometric data, etc.) are not collected or processed on the platform. It is the organization's responsibility to ensure that such data is not entered into open-ended fields.
SECTION 4Purposes of processing
- Concluding the subscription agreement, opening the organization workspace and providing the service,
- Creating user accounts, authentication and authorization,
- Running evaluation cycles, sending invitations/reminders to participants and collecting responses,
- Producing aggregated reports with threshold rules applied,
- Invoicing, collection, accounting and keeping financial records,
- Handling support requests and managing customer relations,
- Ensuring platform security, preventing abuse and unauthorized access, maintaining the audit trail,
- Improving the service through aggregated and anonymous usage statistics,
- Fulfilling legal obligations and responding to requests from competent public authorities,
- Sending promotional and informational messages where you have given explicit consent.
SECTION 5Legal grounds for processing
The purposes above rely on the following legal grounds under Article 5 of the Law:
- Art. 5/2-(c) — Directly related to the conclusion or performance of a contract: subscription, account opening, service provision, invoicing.
- Art. 5/2-(ç) — Compliance with the data controller's legal obligations: tax legislation, e-invoicing, statutory retention and reporting duties.
- Art. 5/2-(a) — Expressly provided for by law: records and notifications mandated by legislation.
- Art. 5/2-(e) — Establishment, exercise or protection of a right: system and correspondence records constituting evidence in the event of a dispute.
- Art. 5/2-(f) — Legitimate interest: platform security, abuse prevention, measuring and improving service quality (provided fundamental rights and freedoms are not harmed).
- Art. 5/1 — Explicit consent: Obtained only for commercial electronic messages and non-essential preferences; withholding it does not prevent provision of the service and it may be withdrawn at any time.
SECTION 6Method of collection
Personal data is collected electronically, by fully or partially automated means, through the following channels:
- Demo request, contact and signup forms on the website,
- User actions in the organization panel, the God Mode administration panel and the evaluator portal,
- Correspondence conducted via e-mail, SMS and support records,
- Transaction result notifications returned by the payment institution,
- Strictly necessary session and security cookies, and server access logs.
SECTION 7Transfer of personal data
In accordance with the conditions in Article 8 of the Law, your personal data is transferred to the following parties only to the extent necessary to provide the service:
- Payment institution
- iyzico Ödeme Hizmetleri A.Ş. — to execute and verify the payment transaction.
- SMS provider
- NetGSM İletişim ve Bilgi Teknolojileri A.Ş. — to send evaluation invitations, reminders and verification codes.
- E-mail provider
- euro.message (Related Digital) — to deliver transactional e-mails.
- Hosting / infrastructure
- Contracted infrastructure providers supplying server, backup and monitoring services.
- Accountant / auditors
- To fulfil accounting and statutory audit obligations.
- Competent public authorities
- Within the scope of statutory information and document requests, to the extent requested.
- Subscribing organization
- For evaluation data; the organization is the controller of its own data and accesses reports subject to threshold rules.
Transfers abroad
Your personal data is not transferred abroad; payment, SMS, e-mail and hosting services are obtained from providers established in Türkiye. Should a transfer abroad become necessary for any component of the service, no transfer will be made unless the conditions in Article 9 of the Law are met, and this notice will be updated beforehand.
SECTION 8Retention periods and destruction
Personal data is retained for as long as the purpose of processing requires and for the minimum periods prescribed by applicable legislation; at the end of the period it is deleted, destroyed or anonymized within periodic destruction processes.
- Account and user data
- For the duration of the subscription relationship; after it ends, subject to statutory limitation periods.
- Evaluation data
- While the subscription is active and for a maximum of 2 years after it ends.
- Invoices and financial records
- 10 years pursuant to the Tax Procedure Law and the Turkish Commercial Code.
- Audit trail and security logs
- At least 2 years; records relating to security incidents are additionally retained until the incident is resolved.
- Demo/contact form records
- A maximum of 2 years from conclusion of the request.
- Marketing consents
- Until consent is withdrawn; the withdrawal record is kept for 3 years as evidence.
When the subscription ends, the organization is granted a 30-day export window; at the end of this period data is permanently deleted or irreversibly anonymized within at most 90 days.
SECTION 9Technical and organizational measures
- Each organization's data is stored technically isolated (tenant-scoped) from other organizations; queries are constrained by the organization identifier.
- Passwords, access link tokens, one-time verification (OTP) codes and notification tokens are never stored in plain text; only hash values are kept.
- Authorization is role and permission based; sensitive operations (deactivating a user, resetting a password, exporting data) require a reason and an audit record.
- Export links are time-limited and signed; accesses are written to the audit trail.
- Data in transit is encrypted with TLS; backups are taken regularly and restore drills are performed.
- Access rights are granted on a least-privilege basis and reviewed regularly.
For further detail, see our security page.
SECTION 10Your rights as a data subject
Under Article 11 of the Law, by applying to the data controller you have the right to:
- Learn whether your personal data is processed,
- Request information if it has been processed,
- Learn the purpose of processing and whether the data is used in accordance with that purpose,
- Know the third parties to whom the data is transferred, domestically or abroad,
- Request rectification if the data is incomplete or incorrectly processed,
- Request deletion or destruction within the conditions of Article 7 of the Law,
- Request that rectification, deletion and destruction be notified to third parties to whom the data has been transferred,
- Object to an adverse outcome arising from analysis carried out exclusively by automated systems,
- Claim compensation for damage suffered due to unlawful processing.
SECTION 11How to apply
You may submit your application through the following channels, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller:
- In writing, by wet-signed petition to: [AÇIK ADRES — Mahalle, Cadde, No, İlçe/İl, Posta Kodu]
- Via registered electronic mail (KEP): [KEP ADRESİ]
- With a secure electronic signature or mobile signature, or from the e-mail address you previously notified and that is registered in our systems: kvkk@proref360.com
Your application must include your name and surname, signature (for written applications), Turkish identity number (passport number for foreign nationals), address for notification, e-mail/phone for notification if any, and the subject of your request. Relevant information and documents should be attached.
Applications are concluded free of charge as soon as possible and in any event within 30 days, depending on the nature of the request. Where the process entails an additional cost, a fee set out in the tariff determined by the Personal Data Protection Board may be charged.
If your application is rejected, you find the response insufficient, or no response is given in time, you may file a complaint with the Personal Data Protection Board within 30 days of learning the response and in any event within 60 days of the application date.
If you take part in an evaluation through an organization, that organization is the controller of your data; you should address your application to your organization first. Requests reaching us are forwarded to the relevant organization and the applicant is informed.
SECTION 12Cookies
The platform uses only strictly necessary session and security cookies; no advertising, tracking or behavioural analytics cookies are used. Details are set out in the Cookie Policy.
This privacy notice may be revised due to changes in legislation or in processing activities. The current version is always published on this page and the effective date is amended. This is a courtesy translation; in case of any discrepancy, the Turkish text prevails.