Privacy & Data Security

Last updated: 2026-09-05 · In case of discrepancy the Turkish version prevails.

Privacy and Data Security Policy

This page is a plain-language summary of the KVKK notice and explains how your venture data is protected.

Your venture data belongs to you

Your questionnaire answers, reports and decks are visible only from your account. They are not shared with third parties except where legally required, not used for advertising and not used to train AI models.

Sub-processors

  • Hosting: Railway (US / EU regions) – application and database.
  • AI narrative (optional): Anthropic Claude API – only questionnaire answers and computed figures are sent; name, e-mail and ID numbers are not. The provider does not train on the data.
  • Payments: the payment institution (once integrated) – card data never reaches FIZIB.
  • E-mail: a transactional e-mail provider.

A data-processing agreement and the KVKK standard contract are signed with each sub-processor.

Security measures

  • All traffic is TLS-encrypted; passwords are bcrypt-hashed, never stored in plain text.
  • Database access is role-based and logged; backups are encrypted.
  • Session cookies are httpOnly and secure.

Account deletion and portability

You can delete your account at any time; reports are permanently erased after a 30-day soft-delete window. You can export reports and decks as PDF/PPTX.

Breach notification

If a breach is detected, affected users are notified by e-mail and the Data Protection Board within 72 hours.