Gizlilik Politikası
Son güncelleme: 19 Nisan 2026
[TODO: Lawyer-reviewed intro paragraph. POWAIN, operating from Istanbul, Türkiye, is subject to KVKK (Türkiye) and GDPR (EU) as primary data protection frameworks. This document should explain in plain language what data we collect, why, how long we retain it, and what rights users have.]
Biz kimiz
[TODO: Legal entity name, registered office address in Istanbul, company registration number, VAT/tax number if applicable.]
[TODO: Data controller identification for KVKK and GDPR purposes, contact details for the designated data protection officer or privacy contact.]
Hangi verileri topluyoruz
[TODO: Account data — email, name, authentication credentials. Fitness intake data — goals, training history, equipment access, language preference. Plan data generated by coaches — workouts, nutrition, supplement recommendations. Coaching chat history. Device information for authentication and bug reporting.]
[TODO: Clarify which fields are required vs. optional. Note any sensitive-health-adjacent data (e.g., injury history, dietary restrictions) and the legal basis for processing it.]
Verilerinizi nasıl kullanıyoruz
[TODO: Purposes — delivering the coaching service, matching users to coaches, billing, customer support, product improvement, legal compliance. Each purpose should map to a legal basis under GDPR Article 6 and KVKK Article 5.]
Verileri ne kadar süre saklıyoruz
[TODO: Retention periods by data category. Account data: as long as the account is active plus X months after cancellation. Coaching chat logs: specify period. Billing data: as long as required by Turkish accounting law (typically 10 years). Clarify deletion process.]
Haklarınız
[TODO: Under GDPR (EU users) and KVKK (Türkiye users), rights include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Explain how to exercise each right and expected response time.]
[TODO: Right to lodge a complaint with the supervisory authority — in Türkiye this is KVKK (Kişisel Verileri Koruma Kurumu), in the EU users may contact their local data protection authority.]
Verilerinizi nasıl koruyoruz
[TODO: Technical and organizational measures — encryption in transit and at rest, access controls, incident response, staff training, regular audits. Note any certifications (ISO 27001, SOC 2) if/when applicable.]
Çocuklar
[TODO: Minimum age for use of POWAIN — typically 16+ or 18+ depending on jurisdiction and service type. Policy on accidental data collection from minors.]
Bu politikadaki değişiklikler
[TODO: How users are notified of material changes. Effective date handling. Where prior versions are archived if applicable.]
