This is a courtesy translation. The Turkish version is the legally binding text; in case of any discrepancy the Turkish version prevails. Turkish original (Türkçe)
DRAFT — The periods have been prepared in accordance with the Regulation on the Deletion, Destruction or Anonymization of Personal Data; the periods in square brackets must be finalized with a lawyer.
Personal Data Retention and Destruction Policy
Version: 1.0 · Last updated: 2026-09-29
1. Purpose and principles
Senin Ekip retains personal data only for as long as the purpose of processing requires and the legislation provides. When the period expires, the data is deleted, destroyed or anonymized at the latest within 6 months (in practice, the automatic deletions below run once a day). Automatic deletions are performed by scheduled tasks in the system; manual destructions are recorded and the records are retained for 3 years.
2. Retention periods
All of the deletions below are performed automatically by the system once a day, and their numbers are written to the server logs. “Closure”: the moment the job is cancelled, refunded or completed.
| Data | Period | Basis |
|---|---|---|
| Account information (name, email, phone) | As long as the account is open; immediately when the account is deleted | Performance of the contract |
| In-app messages | 3 years from closure | Regulation on Distance Contracts, Art. 12/A; protection of rights |
| Acceptances of pre-contractual information and of the withdrawal exception | 3 years from closure | Regulation on Distance Contracts, Art. 12/A; proof |
| Acceptances of the terms of use, privacy notice and agreements | As long as the account is open; 3 years after the account is deleted | Proof |
| Request and job completion photos | 2 years from closure (the files are also deleted) | Limitation periods under Art. 16 of Law No. 6502 on Consumer Protection (TKHK) and Art. 478 of the Turkish Code of Obligations (TBK) |
| Profile photo and company logo | When you remove or replace it or delete your account; the file is deleted within 48 hours | Explicit consent (Art. 5/1 KVKK) |
| Uploads not linked to any record | 48 hours | Purpose no longer applies |
| Service provider documents | 2 years after the account is deleted (the files are also deleted) | Art. 6 of the Regulation on Intermediary Service Providers and Service Providers in Electronic Commerce (ETAHS Regulation), protection of rights |
| ID document image (independent pro) | The file is deleted 30 days after verification; the “ID verified” record is kept until the account is deleted | Art. 6 of the ETAHS Regulation; data minimisation (KVKK Art. 4) |
| Closed suspicious activity records | 24 months | Legitimate interest |
| Login codes (one-time) | 30 days | Security |
| Traffic data (IP, port, time, user, request path) | 1 year + 30 days | Law No. 5651 (on the regulation of internet publications) and the related regulation |
| Administrator action records | 5 years | Accountability, protection of rights |
| Invoices, payment records, balance transactions and balance top-up orders | 10 years | Art. 82 of the Turkish Commercial Code (TTK), Art. 253 of the Tax Procedure Law (VUK) |
| Application error logs | Contain no personal data; not written to the database, kept only in the server log | Legitimate interest |
3. Destruction methods
- Deletion: Rendering database records and files inaccessible, including in backups.
- Anonymization: Permanent removal of identity and contact fields in records kept for statistical purposes.
- Backups: Backups are retained for at most 14 days; deleted data is also removed from backups when the backup cycle is completed.
4. Security measures
- Service provider documents are kept in a non-public area; they are opened only to their owner and authorized persons, via a time-limited, signed link.
- Request and job photos are served at unpredictable random addresses; location (GPS) and device information is deleted on upload (JPEG, PNG, WebP).
- Traffic records are kept with a hash linking each line to the previous one (a chain); any subsequent alteration is detectable.
- Administrator access is limited by role and every action is recorded.
- In the event of a data breach, notification is made to the Personal Data Protection Board within 72 hours at the latest from becoming aware of the breach, and to the data subjects as soon as possible.