This is an informational English translation. The Turkish version is the legally binding text; in case of any discrepancy, the Turkish text prevails. Read the Turkish original.
Privacy Policy (KVKK + GDPR)
1. Data Controller
Salim Kızılay (sole proprietorship) — Address: Reşadiye Mahallesi, Yunus Emre 6. Sokak, M. Tüfekçi Apt. 9/12, Çorlu, Tekirdağ · Email: info@appointstart.com · KEP: N/A (sole proprietorship, KEP not mandatory)
2. Categories of Personal Data Processed
Identity/Contact: name, email.
Membership/Transaction: account and subscription status, session records, preference settings.
Payment: billing information and payment status (card data is not stored by us; processed by Lemon Squeezy / Google Play Billing).
Appointment records: customer name, phone number, service name, appointment date/time, and attendance (no-show) outcome.
Consumer account: name, email, phone, appointment history, and reviews written.
Business account and verification: trade name, address, location coordinate, category, opening hours, and identity verification (KYC) result.
Identity documents (business owner): identity/business documents uploaded for owner verification (PDF/JPEG/PNG). Documents are malware-scanned in quarantine, retained only on a clean result, and deleted once verification completes.
Identity verification (consumer): a consumer is asked to verify their identity before writing a review for a second business. The document is uploaded directly to Sumsub — your identity document never reaches us; we retain only the Sumsub applicant id and the verification result (approved/rejected and date). This is also shown on screen before the redirect.
Location: the location a consumer provides for nearby search is resolved in the browser; the only location stored on our servers is the business's own published address coordinate.
Connection credentials: the business's own WhatsApp Business API credentials and SMTP configuration (stored encrypted).
Technical: IP address, device/browser info, log records, cookie data.
SPECIAL CATEGORY DATA — may be processed in this service. The marketplace categories include aesthetic clinics, dental clinics, physiotherapy and psychologists. An appointment record at a business in one of these categories may support an inference about the data subject's health, and may therefore constitute special category personal data under KVKK Art.6 / GDPR Art.9. Such data is processed only with the data subject's EXPLICIT CONSENT (KVKK Art.6/2; GDPR Art.9/2-(a)) and only for the purpose of making the appointment; no diagnosis, treatment or clinical note is collected or stored — the record consists solely of the service name, date/time and attendance outcome. Consent may be withdrawn at any time, after which the relevant records are deleted, subject to statutory retention periods. Other special categories (biometric, racial or ethnic origin, political opinion, philosophical or religious belief, trade union membership, sex life, criminal conviction) are not processed.
3. Purposes of Processing and Legal Bases
Provision of the service and performance of the contract — KVKK Art.5/2-(c); GDPR Art.6/1-(b).
Billing and legal obligations — KVKK Art.5/2-(ç); GDPR Art.6/1-(c).
Security, fraud prevention and service improvement (legitimate interest) — KVKK Art.5/2-(f); GDPR Art.6/1-(f).
Marketing communications — only with explicit consent — KVKK Art.5/1; GDPR Art.6/1-(a). Under E-Commerce Law 6563 Art.6, every commercial message we send includes a clear sender label and an unsubscribe link; sending continues until consent is withdrawn.
Privacy by Design (GDPR Art. 25)
AppointStart integrates privacy protection into the product design phase: data minimization, purpose limitation, privacy-by-default settings, and automatic anonymization/deletion at the end of retention periods are applied by default.
4. Transfer and Cross-Border Transfer
Data may be shared with the following service providers for the purpose of delivering the service. Where servers outside Türkiye are used, transfers are made under the safeguards of KVKK Art.9 and GDPR Chapter V.
• Google Cloud Platform (hosting, EU) — Cloud Run europe-west3 (Frankfurt), Cloud Logging, Secret Manager and Cloud Build. Request bodies, headers and application logs are processed in this environment. Data is held in the EU region; where Google support access is required, SCCs 2021/914 Module 2 apply.
• Cloudflare (edge proxy / TLS termination / WAF, US) — EVERY request to appointstart.com passes through Cloudflare's edge in full (body, headers and URL) and the TLS connection is terminated there. This covers all traffic, appointment records included; it is not a subset. Cloudflare also keeps its own access logs, whose retention is not governed by our retention periods below. It is NOT the hosting provider; hosting is on Google Cloud Platform.
• Neon (managed PostgreSQL, Frankfurt/EU) — tenant data is hosted in the EU region
• Cloudflare Email Sending (outbound email, US) — ALL email the platform sends is submitted to Cloudflare's REST API in the US; the recipient address, the subject and the message body (including the one-time link in the account verification message) reach that party.
• Lemon Squeezy (Merchant of Record, US) — PCI-DSS compliant; card data is not stored by us; SCCs 2021/914 Module 2
• Google Play Billing (subscription purchase, US) — a pseudonymous account identifier is transmitted for purchase verification
• Sumsub (identity verification/KYC, EU) — identity document and verification result for business owners and consumers alike. A consumer uploads the document directly to Sumsub; the document never reaches us, and only the Sumsub applicant id and the verification result are retained
• WhatsApp Business API / Meta Platforms (US) — customer name and phone number, sent only over the business's own connection, for reminder delivery
• Google Maps Platform (US) — business location mapping; consumer location is resolved in the browser and never sent to our servers
5. Retention Periods
Retention periods by data category:
• Account and subscription data: as long as the account is active, plus 5 years after closure (Turkish Tax Procedure Law Art.253).
• Payment and invoice records: 10 years (Tax Procedure Law Art.253 — accounting records).
• Traffic / IP / log records: 6 months.
• Marketing consent: until the relevant preference is withdrawn.
• Cookie consent record (appointstart_consent_v1): until the preference is changed or cleared, and in any case no later than the period stated for that record in the Cookie Policy.
• Identity verification documents: deleted once verification is concluded; the verification result (approved/rejected and date) is retained while the account is open.
• Sumsub applicant id: retained alongside the verification result while the account is open, so the same verification is not demanded twice and the result can be traced to the application it belongs to.
• Appointment and attendance records: while the account is open; deleted after account closure, subject to statutory retention periods.
• Reviews: until unpublished or the account is deleted.
When these periods end, data is deleted, destroyed, or anonymized. Periods may be extended where required by legal obligations.
6. Your Rights
You may exercise your rights under KVKK Art.11 and the GDPR (access, rectification, erasure, restriction of processing, portability, objection) via info@appointstart.com. Requests are resolved within 30 days at the latest. You may also request data export and erasure from your account panel.
Right to lodge a complaint: in Türkiye, with the Personal Data Protection Authority (https://www.kvkk.gov.tr); in the EU, with the data protection authority of your member state of residence.
7. Security
Sensitive data is protected with at-rest encryption; access rights are limited on a least-privilege basis. Regular backups and restore testing are performed.
8. Cookies
Cookie usage is described in the separate Cookie Policy.
9. Children's Data
The service is not directed at persons under 18; we do not knowingly collect data from them.
10. Automated Decision-Making and Profiling
PROFILING — is performed in this service. A punctuality (trust) score is computed for a consumer account from the attended/no-show outcomes recorded on past appointments. The score is derived SOLELY from attendance outcomes recorded by businesses; cancelling an appointment does not lower it, and the appointment's content, service name and business category do not enter the score.
The score does not by itself produce a binding decision: accepting or refusing a booking request is always the business's own human decision. Because the score may feed into that decision, your rights under GDPR Art.22 and KVKK Art.11 are reserved — you may contest your score, learn which outcomes it is composed of, request correction of an incorrect attended/no-show record, and request human intervention.
Review ratings are also shown on a business profile; these are consumers' own statements, not an automated score.
11. Data Breach Notification
When a suspected data breach is detected, an internal assessment begins within 24 hours. If personal data of affected users is confirmed to be at risk, a notification is sent to the KVKK Board and/or the relevant EU member state data protection authority within 72 hours.
For high-risk breaches, affected users are directly informed within 7 days.
12. EU Representative and VERBİS Registration
GDPR Art.27 EU representative: not currently designated; we are assessing the exemption threshold given that active EU-targeted data processing is not performed. If a representative is appointed, this section will be updated.
VERBİS (Data Controllers Registry) registration: we are evaluating the annual thresholds set by the KVKK Board for sole proprietorships. If registration becomes mandatory, we will register and update this section accordingly.