Privacy
Policy

At TurkGateway, your administrative data is treated as a matter of personal sovereignty. Our platform is built on data ephemerality, local-first storage, and zero-knowledge principles.

KVKK No. 6698 Compliant
AES-256 Encryption
Zero credential storage
Last Updated: May 2026 · Version 3.0

KVKK Compliance

In accordance with the Turkish Personal Data Protection Law (KVKK No. 6698), TurkGateway acts as a data processor for the information you provide during AI consultations. We implement rigorous technical and administrative measures to protect your sensitive data.

Data Controller

TurkGateway Platform, registered under Turkish commercial law.

Legal Basis

Explicit consent obtained at registration and renewed on material change.

DPO Contact

privacy@turkgateway.ai — respond within 30 days per KVKK.

Supervisory Authority

Kişisel Verileri Koruma Kurumu (KVKK Board), Ankara, Turkey.

Data Collection & Usage

We collect only the minimum data necessary to deliver your roadmap and automation services.

01

Conversational Data

Chat logs are stored primarily in your local browser (localStorage). When sent to our AI Agents, data is encrypted in transit and used strictly to generate your roadmap — not for training, profiling, or advertising.

02

Identity Credentials (RPA)

When using our bot for e-Devlet or MERSİS synchronization, your T.C. Kimlik and password are held only in secure, stateless volatile memory for the duration of the automation task. We NEVER persist these credentials in any database.

03

Account Data

Name, email address, and hashed password stored in our secure database (bcrypt, salted). Payment data is never stored — processed exclusively via iyzico PCI-DSS Level 1.

04

Usage Analytics

Anonymous, aggregated session data (page views, feature usage) to improve the product. No personally identifiable information is included.

Document & Biometric Data

Security Standard

Documents uploaded for permit processing are stored in encrypted S3 buckets with AES-256-bit encryption at rest and TLS 1.3 in transit. Access is restricted exclusively to the Agentic sub-routines required to extract metadata for your application.

  • Documents are auto-deleted 30 days after your session closes unless you request extended storage.
  • Passport scans are never used for identity verification beyond the declared automation task.
  • Face photos (if any) are processed locally and never sent to third-party facial recognition services.
  • You may request immediate deletion of all uploaded documents at any time via Settings → Data.

Third-Party Data Sharing

TurkGateway does NOT sell your data to marketers or data brokers. Data is only shared with:

Turkish Government Portals

Upon your explicit RPA command only (e-Devlet, MERSİS, e-İkamet).

iyzico Payment

Billing name and amount for subscription processing. PCI-DSS Level 1 certified.

Google Gemini AI

Anonymized query text via encrypted API. No PII sent. Data not used for training.

Cloud Infrastructure

AWS (Frankfurt EU region) for document storage. GDPR & KVKK compliant.

x

Third-party advertisers

Never. We do not have advertising partnerships.

Data Storage & Security

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

EU-West

Data residency (Frankfurt)

Our infrastructure is hosted on AWS EU-West (Frankfurt), ensuring data stays within the European Economic Area. We undergo annual penetration testing and maintain SOC 2 Type II compliance. All access to production databases is logged, audited, and requires multi-factor authentication.

Your Rights Under KVKK

Under KVKK Article 11, you have the following rights which you can exercise at any time:

Right to Access

Request a copy of all personal data we hold about you.

Right to Rectification

Correct any inaccurate or incomplete personal data.

Right to Erasure

Request deletion of all your data ("right to be forgotten").

Right to Portability

Export your data in a structured, machine-readable format (JSON).

Right to Object

Object to processing of your data for automated decision-making.

Right to Restrict

Limit how we process your data while a dispute is resolved.

To exercise any right, go to Settings → Data & Privacy or email privacy@turkgateway.ai. We respond within 30 days as required by law.

Data Retention

Chat conversation history

Then permanently deleted unless you opt-in to extended storage.

90 days

Uploaded documents

Auto-deleted after session expiry. Delete instantly from Settings.

30 days

Account data

Deleted within 60 days of account closure.

Account lifetime + 60 days

Payment records

Required by Turkish Tax Law (VUK). Stored by iyzico, not us.

10 years

RPA credentials (TCKN/password)

Never written to disk. Zeroed from memory immediately after bot completes.

Session only

Policy Updates

When we make material changes to this Privacy Policy, we will:

  • Display a prominent in-app banner for 14 days before changes take effect.
  • Send an email notification to your registered address.
  • Maintain an archived version of all previous policies for transparency.
  • Require re-consent for any new processing purpose not covered by your original consent.

This policy is governed by Turkish law. Disputes fall under the jurisdiction of Istanbul courts.