KVKK Privacy Notice
Effective date: 21 August 2026 · Version: v10
Convenience translation: This English version is provided for convenience only. The Turkish original ("Netlik KVKK Aydınlatma Metni") is the governing text; in case of any conflict, the Turkish version prevails.
This notice has been prepared pursuant to Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (the "KVKK") by Mustafa Uğur Serez, a natural person acting as data controller (the "Data Controller"). Address for service: Liman Mahallesi, 23. Sokak, No: 2/5, Konyaaltı/Antalya/Türkiye · E-mail: netlikapp@gmail.com
In this notice, service providers are identified by function and region; Article 10 of the KVKK and Article 13 of the GDPR permit disclosure of recipients or categories of recipients. The current legal names, functions and countries of those providers are published and kept up to date at https://www.netlikapp.com/en/sub-processors.
1. Categories of personal data processed
- Identity and contact: full name, e-mail, phone number (optional).
- Account and transaction security: password (encrypted), session records, anonymized IP, truncated device information, notification identifier.
- Technical usage data: limited analytics events in the production mobile App, such as feature, screen, result, count and risk category. Raw message, document, health-note or child-profile content is not added to analytics events. No crash reporting is used.
- Family and child-related data: family memberships and invitations; child profile (name, date of birth, school/class, teacher, school transport, body measurements, notes). Data about a child is entered only by a parent/guardian. The family structure is based on user declarations; the Data Controller is not obliged to verify their accuracy.
- Special categories of data (if you enter them): allergy, blood type, regular medication and emergency notes you may add to the child profile and documents you upload under the health category may contain health data. Such data is processed only on the basis of your explicit consent and for the purpose of providing the service to you; whether to fill in these fields is your choice. Only users with full parent/guardian authority can enter or change this data.
- Coordination records: calendar/handover events, messages, expense and decision requests, dispute records, documents including court decisions, reports, checklists, personal journal.
- Optional AI and OCR content: only the calm-language draft, expense receipt or protocol/court document you select for an action you initiate, together with the context necessary for that action. In protocol/court document extraction the entire document is transmitted to the provider (see 3/A). Full message history or child profiles are not sent automatically.
- Document bridge data: when receiving a document from a third party who is not a Netlik user — the masked IP address and truncated browser information of whoever opens the link, the file they upload, and the e-mail/phone you entered as your own note when preparing the link (optional).
- Subscription data: plan and purchase status; the randomly generated user number transmitted to the subscription verification provider.
2. Processing purposes and legal bases
| Purpose | Legal basis (KVKK) |
|---|---|
| Membership, authentication, provision of the service, shared record system | Art. 5/2-c: establishment/performance of a contract |
| Information security, prevention of abuse, transaction records | Art. 5/2-f: legitimate interest |
| Compliance with legal obligations, responses to official requests | Art. 5/2-ç: legal obligation |
| Establishment, exercise and protection of rights (record/evidence retention) | Art. 5/2-e |
| Resolution of data subject requests and the completion service e-mail | Art. 5/2-c, Art. 5/2-ç and the nature of the request |
| Processing of notes and documents that may contain health data | Art. 6: explicit consent |
| Calm-language, receipt OCR and protocol/document extraction at your request | Art. 5/2-c: performance of a contract; explicit consent under Art. 6 for special-category content |
| Receiving a document from a third party via the document bridge and keeping evidence of the upload | Art. 5/2-c and Art. 5/2-f |
| Delivering the family invitation by e-mail (the invitee's address) | Art. 5/2-f: legitimate interest |
| Receiving, reviewing and resolving reports of inappropriate content | Art. 5/2-ç and Art. 5/2-f |
| Subscription purchase and entitlement verification | Art. 5/2-c: performance of a contract |
| Limited product analytics | Art. 5/2-f: legitimate interest |
Personal data is not processed for marketing, advertising or profiling; data relating to the child is never used for commercial communication.
3. Transfers
Your personal data may be transferred, limited to the stated purposes and the data required, to the following categories of recipients. The current names and countries of the providers in these categories are listed at https://www.netlikapp.com/en/sub-processors.
- Cloud infrastructure provider (EU / Germany): account, family/child, coordination, document, storage and server-function data.
- Push notification provider (USA): the device notification identifier and general notification data containing no sensitive detail.
- Product analytics provider (USA): limited feature, screen and result events from the production mobile App; events sent by Netlik do not contain raw message, document, health-note or child-profile content.
- AI provider (USA, paid service): only content involved in calm-language, selected receipt OCR, and selected protocol or court-document extraction actions that you initiate. Full message history or child profiles are not sent automatically. Under the paid-service terms, prompts, files and responses are not used for product improvement or model training. The provider may retain prompts, context and outputs for 55 days for abuse monitoring and legal obligations; suspicious use may be reviewed by authorized personnel.
- Service e-mail provider (USA): the recipient e-mail address and fixed template text for sign-up verification, family invitation, account-deletion completion and content-report outcome e-mails. For the deletion notice the recipient information is kept briefly in an encrypted queue and cleared after delivery.
- Web hosting provider (USA): limited request-level technical records generated when hosting https://www.netlikapp.com and app.netlikapp.com.
- App stores and subscription verification provider (USA): purchase and subscription status and the randomly generated user number of your account; Netlik does not receive full payment card data.
- People you invite and professionals you authorize: only records within the family space, duration and access scope you define.
Regular transfers to providers abroad are carried out on the basis of an adequacy decision or an applicable appropriate safeguard under KVKK Article 9. Where a standard contract is used, the statutory notification period is observed. Explicit consent is used as an exceptional transfer ground only for occasional transfers that meet the statutory conditions where no adequacy decision or appropriate safeguard exists. Transfers to competent authorities and courts are limited to cases required by law. Your data is not sold to third parties for advertising.
3/A. Scope of protocol and court-decision extraction
Only you initiate this action. When you do, the entire document is transmitted to the AI provider; no single part of it (for example, only the operative provisions) is filtered out and sent on its own. The extraction looks for fourteen headings: custody and visitation schedule, support payments, expense sharing, school, school transport, activities, handovers, health-related decisions, emergencies, checklists, day swaps, authorised persons, travel consent and contact schedule; provisions falling under none of these headings are not converted into structured data. The result is shown to you as a summary first and written into your records only with your approval.
4. Collection method
Your data is collected electronically via forms on the app and the website, record creation screens, file uploads, uploads received from third parties through a document bridge link, and automatically during the operation of the service (logs, notification identifier).
5. Retention
Data is retained for the duration of membership; audit, evidence and data protection application records, and records subject to statutory retention obligations, are retained for the periods set by the applicable law. A verified account deletion request is processed automatically — without a 30-day waiting period — in the first 01:00 Europe/Istanbul run following the request; an authorized administrator may process it earlier with fresh two-factor verification. Thirty days is the maximum response time for concluding an application, not a waiting period.
On account deletion. Credentials and directly identifying profile data (name, e-mail, phone, profile image, notification identifiers, in-app notifications) are deleted; sign-in is permanently closed and the account cannot be reactivated.
Coordination records the two parents created together are not deleted; those records also belong to the other parent and are retained under Art. 5/2-e for the establishment, exercise and protection of rights. The name in the record is replaced by a fixed label. This is pseudonymisation, not anonymisation: the record stays attached to the same participant identifier and, in a two-person family space, the other parent continues to know whose record it is.
Retention period for shared records: for as long as the family space is active; when the last remaining full-access parent also deletes their account the purpose ends and the records are deleted in full 2 years after that date.
Under an active legal hold, only the necessary and proportionate data explicitly selected in the decision is preserved for the relevant scope and duration. Deletion evidence is retained for at least three years. The encrypted temporary recipient information used until the completion e-mail is sent is cleared after delivery. Short-lived technical counters are deleted after 7 days and server transaction logs after 30 days.
6. Your rights under KVKK Art. 11
You have the right to learn whether your personal data is processed; to request information; to learn whether it is used in line with its purpose; to know the third parties to whom it is transferred domestically or abroad; to request rectification if processed incompletely or inaccurately; to request deletion/destruction within the framework of KVKK Art. 7; to request notification of these operations to third parties to whom data has been transferred; to object to a result to your detriment arising from analysis exclusively by automated systems; and to claim compensation if you suffer damage.
You may submit applications, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller, in writing to Liman Mahallesi, 23. Sokak, No: 2/5, Konyaaltı/Antalya/Türkiye, from the e-mail address registered to your account to netlikapp@gmail.com, or through the application flow in the App. Applications are concluded within 30 days at the latest and free of charge as a rule; if the operation additionally requires a cost, the tariff set by the regulations may be applied. You can also directly initiate data export and account deletion requests from within the App. This 30-day period does not mean an account deletion request will be held; the verified technical deletion flow runs according to the first-01:00 schedule described above.