Last updated: 2026-09-05 · In case of discrepancy the Turkish version prevails.
Prepared under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK").
FIZIB (details on the Legal Notice page) is the data controller.
| Category | Data |
|---|---|
| Identity | Name (optional) |
| Contact | E-mail address |
| Transaction security | Password (hash only), IP address, session and log records |
| Customer transactions | Purchase records, invoice details (name/company, address, ID/tax number – only if provided for an invoice) |
| Financial | Transaction reference from the payment institution; card data is never stored by FIZIB |
| Marketing | Commercial message consent (optional) |
| Venture data | Questionnaire answers (planned venue, location, budget, personal equity and similar information that may relate to you) |
Data may be transferred, limited to the purpose, to the hosting provider (Railway – US/EU), the AI provider (Anthropic – US; only questionnaire answers and computed figures, never identity or contact data), the payment institution, the transactional e-mail provider, the accountant and e-invoice integrator, and competent public authorities. Cross-border transfers are made under the Board's standard contractual clauses pursuant to KVKK art. 9 and notified to the Board.
Data is collected electronically through web forms, cookies and the payment institution.
| Data | Period |
|---|---|
| Account data | Until deletion + 1 year |
| Invoices and distance-sale records | 10 years (tax and commercial codes); contract texts at least 3 years |
| Traffic/log records | 2 years (Law 5651) |
| Marketing consent | 3 years after withdrawal |
| Reports and decks | Account deletion + 30-day soft delete |
You may learn whether your data is processed, request information, learn the purpose and the recipients, request correction or erasure, object to automated results and claim compensation. Send requests to destek@fizib.co; we respond within 30 days.
TLS encryption, bcrypt password hashing, role-based access, encrypted backups and access logging are applied. Breaches are notified to the Board within 72 hours and to affected persons promptly.
The platform is not intended for persons under 18.