Note: This page is an English translation of hepy.app's original Turkish-language privacy notice, prepared under Turkey's Personal Data Protection Law (KVKK, Law No. 6698) — not the EU's GDPR. In the event of any discrepancy between this translation and the original, the Turkish version shall prevail.
HepyApp Personal Data Protection and Privacy Policy
Hepy.app (“we,” “us,” or “our”) is committed to protecting the privacy of our users. This Privacy Policy explains how your personal information is collected, used, stored, and disclosed by Hepy.app. This Privacy Policy applies to our application and our website at www.hepy.app, along with all related subdomains (collectively, our “Service”). By accessing or using our Service, you acknowledge that you have read, understood, and agreed to the personal data collection, storage, use, and disclosure practices described in this Privacy Policy and our Terms of Service.
1. Definitions
The terms used in this section are defined to make the agreement clearer and easier to understand. These definitions clarify what the terms used throughout the rest of the text mean.
- Personal Data: Any information relating to an identified or identifiable natural person (e.g., name, surname, email, IP address).
- Data Subject (Relevant Person): The natural person whose personal data is processed.
- Data Controller: The person or entity that determines the purposes and methods of processing personal data and is responsible for establishing and managing the data recording system. In this text, this is Hepy.app.
- Cookie: Small data files left on a user's device by visited websites, used to recognize the device.
- Explicit Consent: A freely given consent statement on a specific matter, based on information.
- Service: All software solutions, integration services, notification services, and user panels provided by Hepy.app.
- Third Party: Persons or entities not directly affiliated with Hepy.app but to which data is transferred for the fulfillment of certain services (e.g., email service providers, hosting companies).
2. What Data Do We Collect?
As Hepy.app, we collect various personal data from our users in order to provide and improve our services and to fulfill our legal obligations. This data may be collected automatically or manually during users' interactions with the system.
Personal Data We Collect:
- Identity Information: Name, surname; username
- Contact Information: Email address; phone number; address information (where necessary for invoice/document delivery)
- Transaction and Usage Data: Service requests, transaction history; submitted forms, support records; feedback content
- Device Information: IP address; browser type and version; operating system information; device model and type; location (subject to user consent)
- Cookie Data: Session information; pages visited; visit duration and preferred language
This data is collected solely for the purpose of providing services and improving user experience. Under KVKK, no processing is carried out for any purpose other than a legitimate one.
3. Methods of Collecting Personal Data
Hepy.app collects personal data through the following methods. These methods cover both data provided directly by users and data collected systematically.
- a) Data Collected Through Direct User Interactions
- Data manually entered through user actions such as registration, form completion, support requests, or quote requests
- Information provided via email and phone
- Communication content from correspondence via WhatsApp, SMS, or live support
- b) Data Collected Through Automatic Methods
- Data obtained through cookies while using our website or applications
- Session and transaction records
- Log records such as IP address, browser information, access date/duration
- Location data from the device (where permission has been granted)
- c) Data Received via Third-Party Integrations
- User data received via integrated tools such as the WhatsApp Business API, email service providers (e.g., MailerLite, SendGrid), and notification services
- Data that users have made publicly available on social media platforms
- Information and requests transferred from authorized business partners
All data collected through these methods is processed and stored solely for the purposes stated in this policy.
4. Purposes of Processing Personal Data
Collected personal data is processed for the purposes below, in accordance with the data processing conditions set out in Articles 5 and 6 of the KVKK:
- a) Service Delivery and Process Management
- Creating and managing user accounts
- Receiving, tracking, and resolving service requests
- Ensuring the proper functioning of services provided (e.g., notifications via email, SMS, WhatsApp)
- Providing technical support for device or software issues
- b) Development and Improvement
- Improving service quality
- Personalizing user experience
- Improving products/services by analyzing faults, disruptions, and feedback
- c) Communication and Information
- Informing users about service-related processes (e.g., maintenance notices, delivery status, new feature announcements)
- Responding to information or transactions requested by the user
- Communicating directly during support processes
- d) Fulfillment of Legal Obligations
- Issuing and retaining invoices
- Providing information requested by courts, public prosecutors, and official authorities
- Managing consent, objection, deletion, and update requests received under KVKK
- e) Marketing and Campaign Activities (with Explicit Consent)
- Informing users, with their consent, about new services, campaigns, and special offers
- Conducting analysis for the promotion of services offered through the platform
Personal data is never used for any purpose outside those stated in these clauses.
5. Legal Grounds for Processing Personal Data
Hepy.app processes personal data based on the following legal grounds set out in Articles 5 and 6 of the KVKK:
- a) Explicit Consent — With explicit consent obtained from the user, for: campaign, promotion, and advertising notifications; sharing of location information; and marketing-related data transfers to third parties
- b) Establishment or Performance of a Contract — Data processing activities necessary to provide our services, create accounts, fulfill requests, and provide support
- c) Fulfillment of Legal Obligations — In cases such as taxation, invoicing, retention periods, and responding to requests from official authorities
- d) Legitimate Interest — Ensuring service security; fraud prevention; on-site performance measurement; making system improvements by analyzing user experience
- e) As Stipulated by Law — Data processing required under legislation such as Law No. 5651, the Turkish Commercial Code, and Law No. 6698 (KVKK)
Data is processed only within these legitimate and legal grounds and is never used outside its intended purpose.
6. Retention Period for Personal Data
Hepy.app retains your personal data only for as long as required by the purposes of processing, or for as long as legally required.
Retention Period Principles:
- Data is retained for as long as needed to complete service delivery and related activities.
- Invoice, record, and transaction information is retained for at least 10 years under the Tax Procedure Law and related legislation.
- Explicit consents obtained under KVKK are retained for as long as that consent remains valid.
- Daily data such as email, support, and transaction history is deleted or anonymized within a maximum of 180 days after the user account is deleted.
- Temporary, consent-based data such as location is retained in the system only for the duration of the consent.
Deletion and Anonymization:
Once data no longer serves its processing purpose, it is either:
- Completely deleted from the system, or
- Anonymized so that it can no longer be used to identify an individual.
These processes are audited through periodic checks in accordance with Article 7 of the KVKK.
7. Security of Personal Data (Protective Measures)
Hepy.app applies robust technical and administrative security measures to protect your personal data against unauthorized access, disclosure, loss, misuse, destruction, or alteration.
Technical Security Measures
- Database and server access is protected with multi-layer authentication.
- Data is transmitted over secure connections (HTTPS/SSL).
- Passwords and sensitive information are stored using one-way cryptographic algorithms.
- Server access logs are regularly monitored and audited for security vulnerabilities.
Administrative Security Measures
- Access rights are restricted according to job roles.
- Employees and business partners are informed of KVKK and privacy obligations and are required to sign confidentiality agreements.
- Access to data is granted only on a "need to know" basis.
Physical Security Measures
- Systems housing data are hosted in physically secured facilities.
- Backup systems are kept in isolated environments to guard against potential data loss.
Additional Assurance:
Although the measures taken are of a high standard, 100% security cannot be guaranteed on the internet. However, in the event of a breach, the relevant individual and the Board will be notified in accordance with Articles 12 and 14 of the KVKK.
8. Sharing of Personal Data with Third Parties
Hepy.app shares your personal data with third parties in a manner consistent with confidentiality and only for specific purposes. This sharing is carried out in accordance with Articles 8 and 9 of the KVKK.
a) Sharing with Service Providers
Limited data sharing may occur, to the extent necessary, for the provision of the following services:
- Server and hosting services (e.g., data center companies)
- Email and SMS delivery infrastructure
- Payment and invoicing systems
- Customer service software
- Cloud backup services
Confidentiality agreements are made with these third parties, and data is used only for the purpose of fulfilling the service.
b) Sharing Due to Legal Obligations
In the following situations, personal data may be shared with legal authorities:
- Court orders, prosecutorial requests, official correspondence from administrative authorities
- Requests from public institutions during tax, audit, and invoicing processes
c) Sharing with Business Partners and Suppliers (where explicit consent has been obtained)
- Within the scope of marketing activities such as email campaigns, surveys, and promotions
- With firms offering campaigns or offers, based on the user's explicit consent
d) Business Transfers and Restructuring
In the event of a merger, acquisition, asset sale, or restructuring of Hepy.app, user data may be transferred only to a third party that will maintain the same privacy standards.
Data is never marketed, sold, or rented out without permission.
9. Transfer of Data Abroad
Hepy.app fully complies with the provisions of Article 9 of the KVKK regarding the transfer of personal data abroad.
Default Principle: As a rule, personal data is stored and processed domestically.
Exceptional Cases: Where certain foreign-based service providers are used (for example, email infrastructure, cloud backup, analytics tools);
- Data transfer takes place only based on the explicit consent of the relevant person,
- or to safe countries announced by the Board under the KVKK.
Where the Board has granted approval, transactions are carried out using data transfer protocols that include an "adequate protection commitment."
Technical Measures: Data transferred abroad is limited strictly to what is necessary, and encrypted communication protocols (such as TLS) are used during transfer.
10. Rights of the Data Subject (User) Under the KVKK
Under Article 11 of Law No. 6698 on the Protection of Personal Data, you may apply to Hepy.app to exercise the following rights:
Your Rights as a User:
- To learn whether your personal data is being processed
- To request information regarding processing, if it has taken place
- To learn the purpose of processing your personal data and whether it is used in accordance with that purpose
- To know the third parties, domestic or abroad, to whom your personal data is transferred
- To request correction of incomplete or inaccurate data
- To request deletion or destruction of data in accordance with the KVKK
- To request that the above requests be notified to third parties to whom the data has been transferred
- To object to a result that arises to your detriment through the analysis of processed data exclusively via automated systems
- To claim compensation for damages arising from unlawful processing of data
How to Apply:
To exercise these rights, you can contact us through the following channels:
Requests will be answered free of charge, in compliance with the KVKK, within 30 days at the latest.
11. Cookies and Similar Technologies
As Hepy.app, we use cookies and similar technologies to improve user experience and ensure our system operates more effectively.
- What Is a Cookie?
Cookies are small text files saved to your device by your browser when you visit a website. They are used to remember pages visited, your session information, and your preferences.
- Types of Cookies We Use:
- Necessary Cookies: Required for the secure operation of our system and basic functions (login, form submission).
- Functional Cookies: Used to remember settings such as the user's language preference and theme selection.
- Analytical Cookies: Allow us to measure performance by analyzing how visitors use the site (e.g., Google Analytics).
- Marketing/Tracking Cookies: Allow ads to be shown to users based on their interests (works only with explicit consent).
- Managing Cookie Preferences:
Users can block, delete, or allow only certain types of cookies through their browser settings. However, if necessary cookies are disabled, some system functions may not work properly.
- Personal Data Content:
Hepy.app does not store personally identifiable data (such as name, phone, or email) in cookies. Cookies contain only technical data.
12. Children's Privacy
Hepy.app services do not target individuals under the age of 13, and we do not knowingly collect personal data from this age group.
- Users Under 13:
- Hepy.app does not knowingly collect data from children under the age of 13.
- If a parent or guardian discovers that their child has submitted personal data to the platform without authorization, they should contact us.
- In such a case, the data in our system will be reviewed immediately and deleted if necessary.
- Parental Responsibility:
Parents or legal guardians should supervise their children's internet use and ensure the platform is used only under adult supervision.
- Legal Compliance:
This clause has been prepared in compliance with both the KVKK and the Guide on the Protection of Children's Personal Data (published by the KVKK Board).
13. Changes to the Privacy Policy
Hepy.app may periodically update this Privacy Policy due to legal requirements, service changes, or user security considerations.
- Notification of Changes:
- If a significant change is made to the policy:
- A visible announcement will be published on our website,
- and, where necessary, the user will be informed via email or an in-system notification.
- Effective Date:
The updated version takes effect from the date it is published on www.hepy.app.
- Acceptance Statement:
If a user continues to use the platform after changes are made to the policy, they are deemed to have accepted those changes. If they do not accept them, the user may delete their account and stop using the system.
- Responsibility to Monitor:
The user is responsible for keeping track of updates to the Privacy Policy.
14. Contact Information and Application Methods
For any request, complaint, or information request regarding your personal data, you can contact us through the following communication channels.
- Application Methods:
- Users can exercise their rights under the KVKK through any of the following methods:
- Email: info@hepy.app
- Website: the contact form on https://www.hepy.app
- Written Application: Users requesting to apply may do so via a physically signed petition, provided their address information is shared.
- Content of the Application:
- The application should include the following information:
- First and last name
- Email address and/or phone number
- Subject of the request
- A document or method verifying your identity
- Response Time:
Requests are concluded free of charge within 30 days. However, if the process incurs an additional cost, a fee may be charged according to the tariff set by the Personal Data Protection Board.