Legal Documents
Privacy Policy
This is an English translation of the Turkish Gizlilik Politikası. The Turkish text prevails; this translation is provided for information only.
Last updated: 1 October 2026. Translation of version 3.13.
This policy explains how your personal data is collected, processed, stored, and shared when you use the İmzala.org platform (operated by Codeck Yazılım Anonim Şirketi). It is prepared in accordance with the requirements of the Turkish Personal Data Protection Law No. 6698 (KVKK), GDPR, and CCPA.
For the official KVKK Privacy Notice, see: /kvkk
1. Information We Collect
1.1 Information You Provide Directly
- Identity: first name, surname, date of birth
- Contact: e-mail, phone, postal address
- Corporate: company name, tax number, trade registry information
- Account: password (bcrypt hash, never plain text), profile photo
- Contract content and parties: the documents you upload, signer information, party roles
- Payment: billing address; for recurring payment (subscription / trial), the PayTR payment token plus the last 4 digits, brand, and expiry date of the card. The full card number (PAN) and security code (CVV) remain with PayTR and are not held by us
1.2 Information from Third-Party Identity Providers
- OAuth (Google / Facebook / Twitter): e-mail address, name/surname, and an external identifier (third_party_id) from these providers' APIs
- You are also subject to these providers' own privacy policies
1.3 Special-Category Personal Data: Biometric (KVKK art. 6)
A handwritten signature is not biometric data; face verification is used only with explicit consent
The handwritten signature you draw on the signing screen is stored as a PNG bitmap image; behavioural biometric parameters such as pressure, speed, acceleration, or angle are not recorded. On its own, this image does not constitute biometric data within the meaning of KVKK art. 6. Special-category biometric data is not processed in the standard signing flow.
For some contracts, the party sending the contract may request an optional identity-verification step (face / liveness verification, ID card scanning). When this step is enabled, the related biometric data is processed only with your separate explicit consent; if you do not give explicit consent, no biometric data is collected. The processing, security (KMS-encrypted storage), and retention (at most 1 year) conditions are described in KVKK Privacy Notice §2.5.
1.4 Automatically Collected Technical Data
- IP address (login, signing, viewing)
- Geolocation (detailed coordinates, only with explicit consent)
- Browser type and version
- Device information and operating system
- Page-usage statistics (anonymous, with cookie consent)
- Audit log: application, KMS signing, and Kubernetes API events
- Step records on the signing page (view and button steps; excluding field values and mouse/keyboard movement)
- Session and token information
- Mobile app (iOS, Android): sign-in, registration and profile details; IP address and device information for the session record; crash reports not linked to your account, used to fix app errors. The app does not access location, camera, contacts or the advertising identifier and does not use usage analytics tools.
1.5 Behavioural Data Generated Through Your Account
- User activity history (UserActivity table)
- Notification preferences
- Marketing opt-in status
- Webhook delivery log (corporate users only)
1.6 Data of Persons to be Informed (CC)
When creating a contract, you may add the e-mail addresses of third parties who will not sign but should be kept informed of the process ("Persons to be Informed" / CC). These persons receive an informational e-mail only at the dispatch and completion stages of the contract.
- Data processed: the e-mail address of the person to be informed and their name, if provided
- Purpose / legal basis: performance of a contract (KVKK art. 5/2-c) and legitimate interest (KVKK art. 5/2-f)
- Authority declaration: the user who adds these persons represents that they are authorised to do so; İmzala.org performs the delivery only as a data processor
- Opt-out: every informational e-mail includes an opt-out link; the request is applied immediately
- Retention: retained together with the relevant contract and automatically deleted when the contract is deleted; the independent retention ceiling is 3 years
- Transfer: e-mail delivery takes place through the sub-processor Mailgun (Frankfurt / EU) under the existing DPA
2. How We Use Your Information
The personal data we collect is used for the following purposes:
- Managing your account and authenticating your identity
- Processing your contract flows (creation, dispatch, signing, archiving)
- Adding to documents a timestamp (RFC 3161) issued by TÜBİTAK KamuSM, an electronic certificate service provider under Law No. 5070 (not an eIDAS qualified timestamp)
- Creating a comprehensive audit trail for the legal validity of the contract
- Delivering signed documents and notifications to your parties
- Billing, payment, and recurring charges within subscription / free-trial scope
- Customer support requests and complaints
- Security, fraud prevention, and audit
- Improving the platform and debugging (error and crash records; personal data is masked before sending, kept for 90 days)
- Marketing (only if you have given explicit consent)
- Fulfilling legal obligations (Turkish Commercial Code, Tax Procedure Law, KVKK, GDPR)
3. Sharing Your Information
We do not sell, trade, or rent your personal information to third parties. We share it only with the business partners that are essential to providing the service, within the scope of a contract. We have signed a GDPR-compliant Data Processing Agreement (DPA) with the large majority of our business partners that process personal data; the basis and safeguard for each service provider is stated separately on the Sub-processors page. Technical services that do not receive personal data (for example, timestamp authorities to which only the document's digest value is sent) are outside this scope.
3.1 Infrastructure and Hosting
- Turhost (Türkiye): primary server infrastructure and data storage; the Türk Telekom İstanbul Gayrettepe data centre, which holds a Tier 3 data-centre certification (no separate data processing agreement is signed; the provider's standard service agreement applies; operation and management access of the servers rests with İmzala.org, and the provider's contractual rights are reserved)
- Güzel Hosting (Türkiye): passive backup server; an encrypted copy of production data, kept on disk with AES-256-GCM as İmzala.org's own measure, taken every 15 minutes to the backup server at the Mars Data Center (the key is managed by İmzala.org and not given to the provider; no separate data processing agreement is signed; the provider's standard service agreement and contractual rights are reserved)
- Hetzner Storage Box (Germany): off-site encrypted backup (AES-256 client-side encryption); used temporarily until the migration to a domestic backup destination is complete
- Cloudflare, Inc. (USA): CDN, DNS, WAF, DDoS protection. EU-Home Region is preferred; GDPR DPA plus Standard Contractual Clauses (SCC) are signed
3.2 Communications
- Mailgun (Germany, EU server): e-mail delivery, EU data centre, GDPR DPA signed
- NetGSM (Türkiye): SMS delivery (default)
- Kobikom (Türkiye): SMS delivery (depending on organisation selection)
- Twilio (USA): international SMS (only for selected organisations)
- WhatsApp (Meta Platforms Ireland Ltd., Ireland): signature invitation, reminder, and completion notification, and the support line, if the sending party has enabled the channel. Only the phone number, name and surname, signing link, and message text are sent; document content is not sent. It is an independent data controller, not a sub-processor; a process to complete the appropriate safeguard is under way
3.3 Payment and Document Services
- PayTR (Türkiye): payment processing, supervised by the Banking Regulation and Supervision Agency (BDDK), PCI-DSS Level 1 certified. The full card number (PAN) and security code (CVV) are stored directly by PayTR; İmzala.org does not view or store them. For automatic charges on subscription renewal and at the end of a free trial, İmzala.org stores only the payment token generated by PayTR and the last 4 digits, brand, and expiry date of the card (performance of a contract, KVKK art. 5/2-c). This token is deleted upon cancellation of the subscription/trial or deletion of the account (unless you have separately consented to "save my card" for future use).
- TÜBİTAK KamuSM (Türkiye): timestamp service (RFC 3161); TÜBİTAK KamuSM is an electronic certificate service provider under Law No. 5070 (not an eIDAS qualified timestamp). Document hash values are sent to obtain the timestamp; document content is not sent.
- Sectigo (Europe) SL (Spain, EU): optional EU-valid qualified timestamp (eIDAS). Only the document's SHA-256 digest value is sent; document content, party information, and IP address are not sent.
3.4 Development and Monitoring Tools
- GitHub (USA): source-code management (code only, no user PII is stored)
3.5 Anonymous Signature Verification Tool
You may use the publicly accessible Signature Verification Tool on our site anonymously, without logging in. The document you upload in this tool is held only for a short period (depending on configuration, at most a few days, or not stored at all beyond the moment of processing) in an isolated area for security/misuse review, and is then automatically deleted; the IP address of your connection is retained for 30-90 days with its last octet masked. To check for revocation/timestamp status, calls are made to the relevant ESHS servers (OCSP/CRL/AIA); bot verification is performed with Cloudflare Turnstile. Details: Signature Verification Tool Privacy Notice. The legal basis for this processing is legitimate interest (KVKK art. 5/2-f). Do not upload a document belonging to someone else.
3.5 Marketing and Analytics (only with cookie consent)
- Google Tag Manager + Google Analytics 4: site usage analytics, anonymous user identifier
- Microsoft Clarity: heat maps and session recordings (PII is automatically masked)
- Meta Pixel (Facebook / Instagram): browser-side advertising conversion tracking
- Meta Conversions API (CAPI): server-side advertising conversion tracking. Your e-mail and phone number are sent hashed with SHA-256 (not raw), for match-rate purposes. Raw PII never goes to Meta.
- Google Ads + Enhanced Conversions: advertising conversion tracking. Under Enhanced Conversions, your e-mail/phone is sent to Google Ads hashed with SHA-256 (not raw PII).
3.5.1 Server-Side Measurement (sGTM, kx7m2.imzala.org)
Marketing measurement traffic first passes through our own server (the subdomain kx7m2.imzala.org, a Server-Side Google Tag Manager hosted in our data centre in Türkiye), and is then forwarded to Google Analytics 4 / Meta CAPI / Google Ads services. Your browser does not connect directly to advertising and analytics providers. This architecture:
- Gives full control over the data flow: what information is shared is checked server-side
- If cookie consent is refused, no marketing event is sent at all (server-side enforcement)
- PII masking/encryption is performed on our server; raw data never goes to a third party
- Because primary hosting is in Türkiye, this step does not give rise to a cross-border transfer under KVKK art. 9; for encrypted backups during the migration period, the art. 9 safeguards apply
Third-Party Cookies
The marketing and analytics services above place their own cookies. They become active if you accept cookies; you may decline in the cookie-consent banner or change your settings at any time. These cookies are also subject to the relevant services' own privacy policies:
3.6 Disclosure Required by Law
We may be required to provide information to competent authorities (courts, the Personal Data Protection Authority, the tax office, etc.) under the law or in legal disputes. In such cases, only the data required by the specific request is provided.
4. Data Security
4.1 Technical Measures
- TLS 1.2 / 1.3: Cloudflare + Let's Encrypt, end-to-end encrypted communication
- AES-256: client-side encryption for off-site backups (rclone crypt)
- RSA-2048: key management system (KMS) for the digital signature
- SHA-256: hash algorithm (document integrity)
- Two-factor authentication (MFA): mandatory on all administration panels
- Role-based access control (RBAC): at both user and operator level
- Network isolation: namespace-level isolation with Kubernetes NetworkPolicy
- Web Application Firewall (WAF): Cloudflare
- Antivirus: ClamAV scanning for uploaded files
- Vulnerability scanning: continuous with Trivy (integrated into CI/CD)
- 24/7 monitoring: Prometheus + Grafana + Loki + GlitchTip
4.2 Operational Measures
- Annual security-awareness training for staff
- NDAs and confidentiality agreements for key staff
- Access rights reviewed periodically (every 3 months)
- Regular disaster-recovery drills (last test: April 2026, successful)
- A structured incident-response procedure (5-phase response)
- Proven 4-layer backup: Velero (Kubernetes) + PostgreSQL dump + Proxmox VM snapshot + off-site encrypted backup (AES-256; Hetzner Storage Box during the migration period)
- Backup integrity and audit trail (9 May 2026): a SHA-256 hash and a TÜBİTAK KAMUnet RFC 3161 trusted timestamp are recorded in the audit log for every backup file. The audit log has indefinite retention. Processes comply with KVKK art. 12 (data security) + art. 16 (record-keeping) + eIDAS art. 41 + ISO 27001 A.12.3.1.
We recommend that our users use strong passwords and enable two-factor authentication from their account settings.
5. Data Storage Locations
Your production data is in Türkiye
- Primary data centre: Türk Telekom İstanbul Gayrettepe (Tier 3, Türkiye), via Turhost
- Passive backup server: Mars Data Center (Türkiye), via Güzel Hosting; an AES-256-GCM encrypted copy on disk
- Off-site backup: Hetzner Storage Box (EU, client-side AES-256 encrypted) during the migration period; migration to a domestic destination is under way
- CDN / edge: Cloudflare's global network (EU-Home Region preferred)
The data-centre choice was made with the aim of keeping production data in Türkiye and avoiding a cross-border transfer under KVKK art. 9 for these steps.
6. Certifications and Compliance Roadmap
6.1 Current Compliance
- Law No. 5070 on Electronic Signatures: timestamp infrastructure (RFC 3161) of TÜBİTAK KamuSM, an electronic certificate service provider under Law No. 5070 (not an eIDAS qualified timestamp)
- Law No. 5070, art. 3 / eIDAS Regulation 910/2014: the browser-based digital signature infrastructure (the user's signature image plus the system's commercial certificate plus PAdES B-LTA plus an RFC 3161 timestamp). This signature is an electronic signature within the meaning of Law No. 5070; it is not a secure electronic signature and is not presented as an advanced or qualified signature under EU law. Phone verification and Turkish ID number checks strengthen the evidentiary value but do not change the nature of the signature
- Registered data controller with the KVKK Data Controllers' Registry (VERBIS)
- GDPR: applicable transfer mechanisms (SCC Module 2) are used with respect to data subjects established in the EU; hosting is in Türkiye
- PCI-DSS SAQ A scope: the full card number and security code are processed/stored only by PayTR (PCI-DSS Level 1); the payment token plus last 4 digits stored at İmzala.org fall within SAQ A scope
6.2 Certification Roadmap
The certifications below have not yet been obtained as of the current date; certification processes will be initiated by the target dates.
- ISO 9001:2015 Quality Management System (target: 2026 Q3)
- ISO 27001:2022 Information Security Management System (target: 2027 Q1)
- SOC 2 Type II (target: 2027 Q4)
Our existing infrastructure already meets a significant portion of the technical and operational controls these certifications require; the certification processes cover formal audit and documentation.
7. User Rights
7.1 Rights under KVKK art. 11 / GDPR art. 15-22
- To learn whether your personal data is being processed
- To request information if it is processed (right of access)
- To learn the purpose of processing and whether the data is used in accordance with that purpose
- To know the third parties to whom the data has been transferred
- To request correction where it is processed incompletely or incorrectly
- To request erasure or destruction when the conditions for processing no longer apply: the right to be forgotten
- To download your data in a structured, machine-readable format: the right to data portability
- To request that correction/erasure be notified to third parties
- To object to automated decision-making processes
- To claim compensation for damage arising from unlawful processing
- Marketing opt-out
7.2 Rights You Can Exercise Directly from Your Account
You can exercise the following rights with a single click from your account:
- Download my data (Account → Privacy): all your user data is downloaded as JSON + ZIP (GDPR art. 20 portability)
- Delete my account (Account → Privacy): for accounts with a registered e-mail address, confirmation through an e-mail link valid for 24 hours → 30-day recovery period. For accounts without an e-mail address (registered with a phone number), confirmation is given in the mobile app: a verification code sent to your registered phone and, if your account has a password, your password are requested → 30-day recovery period; on this path, an informational SMS is sent to your registered phone. During the recovery period you can log in and cancel the deletion. At the end of this period your account is permanently closed and your profile, contact and login data are deleted or anonymised. Records subject to a statutory retention obligation (such as signed contracts and signature records, payment and invoice records) are retained for the period required by law; the content of signed documents is not altered, so that their integrity is preserved. At the end of that period these records are also deleted or anonymised. If you cannot use these paths, you can send your request to [email protected].
- Marketing opt-out (Account → Notifications): unsubscribe from all marketing e-mails
- Cookie preferences (the "Cookie Settings" link in the page footer)
7.3 California Consumer Rights (CCPA / CPRA)
Additional rights for California residents:
- Right to know: the categories of personal data collected
- Right of access: a copy of your data
- Right to delete
- Right to correct (CPRA)
- Right to limit the use of sensitive personal information (CPRA)
- Right to opt out of / object to the sale of personal information
We Do Not Sell Your Data
İmzala.org does not sell your personal information to third parties. No "sale" of personal data, as defined under CCPA, takes place. To exercise the CCPA "Do Not Sell or Share My Personal Information" right: [email protected]
7.4 How to Apply
- E-mail: [email protected] or [email protected]
- Registered e-mail (KEP): [email protected]
- Post: Codeck Yazılım Anonim Şirketi, Maslak Mah. Aos 55. Sk. 42 Maslak No: 4 İç Kapı No: 556 Sarıyer / İstanbul
Your applications are answered within 30 days.
8. Cookies
İmzala.org uses cookies and similar tracking technologies to improve your platform experience. You are shown a cookie-consent banner on your first visit.
8.1 Types of Cookies
- Strictly necessary cookies: the core function of the website (session, security, language preference)
- Performance / analytics cookies: GA4, Microsoft Clarity (anonymous site-usage statistics)
- Marketing cookies: Meta Pixel, Google Ads (active only with consent)
For a detailed list with cookie ID, duration, and provider information, see: Cookie Policy
You can change your cookie preferences at any time: the "Cookie Settings" link at the bottom of the page, or through your browser settings.
9. International Data Transfers
Your production data is located in Türkiye (the Türk Telekom İstanbul Gayrettepe data centre). Transfers abroad occur only in the following cases and are subject to legal safeguards:
- Transfer within the EU (encrypted backups during the migration period: Hetzner, Germany; e-mail: the Mailgun EU server): the appropriate safeguard under KVKK art. 9 is applied
- Transfer to the USA (Cloudflare, Twilio, GitHub): Standard Contractual Clauses (SCC) Module 2 signed
- Transfer to Ireland and global infrastructure (WhatsApp / Meta Platforms Ireland, an optional notification channel): a cross-border transfer under KVKK art. 9; Meta is an independent data controller, there is no separate data processing agreement, and a process to complete the appropriate safeguard (the Board's standard contract) is under way
- Transfer to Türkiye (PayTR, NetGSM, Kobikom, TÜBİTAK KamuSM): considered domestic under KVKK art. 9
10. Retention Periods
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Contract PDF, audit trail, metadata | 10 years | Turkish Commercial Code art. 82 |
| Anonymous verification: uploaded document / masked IP + metadata | Document: short period (depending on configuration, at most a few days, or not stored); IP+metadata: 30-90 days (automatic deletion) | Legitimate interest (KVKK art. 5/2-f) |
| Signing, viewing, and transaction IP address; traffic security logs | 10 years | Law No. 5070, Turkish Commercial Code art. 82: non-repudiation of the digital signature and evidentiary integrity |
| Signature image | Until account deletion | Performance of a contract |
| User account | Until account deletion (30-day grace) | Performance of a contract |
| Deleted contract template (template name, description, field layout, any sample party information) | A 30-day recovery window after the deletion request; automatic permanent deletion at the end of that period. If the account is deleted, deletion occurs without waiting for the recovery window. | Performance of a contract (KVKK art. 5/2-c); legitimate interest with respect to the ability to recover from user error (art. 5/2-f) |
| Audit log | 5 years | Audit, ISO 27001 |
| Invoicing and payment | 10 years | Turkish Commercial Code art. 82 (10 years); Tax Procedure Law art. 253 (5 years) |
| Recurring-payment token (card reference, last 4 digits, brand, expiry) | For the duration of the active subscription / trial; deleted upon cancellation or account deletion (if explicit consent for "save my card" was given, until that consent is withdrawn) | Performance of a contract (KVKK art. 5/2-c); explicit consent for card storage |
| Free-trial records (start/end, auto-charge date, cancellation status) | For the duration of the trial + subscription relationship; the related invoice record for 10 years | Performance of a contract, Turkish Commercial Code art. 82 (10 years); Tax Procedure Law art. 253 (5 years) |
| SMS send log | 1 year | Operational |
| Webhook delivery log | 90 days | Operational |
| User activity | 3 years | Legitimate interest |
| OTP / refresh / magic-link tokens | Deleted immediately after expiry | Authentication security |
| Cookie data | Max. 2 years | KVKK + ePrivacy |
| Traffic log under Law No. 5651 | 2 years | Law No. 5651 |
10.1 Data Destruction Policy
- Data whose retention period has ended is automatically deleted or anonymised
- Deletion requests are finalised within 30 days
- Complete cleanup is also carried out from backup systems (at the end of the rotation period)
- Destruction operations are logged and added to the audit records
11. Children's Privacy
Our service is not directed at individuals under 18. We do not knowingly collect personal information from individuals under 18. If we detect that we have, this data is deleted immediately.
12. Data Breach Notification
- Notification to the Personal Data Protection Authority within 72 hours of detecting a breach (KVKK art. 12, GDPR art. 33)
- E-mail notification to affected users based on a risk assessment (GDPR art. 34)
- The affected data categories, measures taken, and recommended actions are explained
13. Policy Updates
This Privacy Policy is updated periodically to reflect legislative changes and application updates.
- Significant changes are announced on our website
- Registered users are notified by e-mail
- New explicit consent may be requested for significant changes
14. Contact Information
Data Controller:
Codeck Yazılım Anonim Şirketi
Maslak Mah. Aos 55. Sk. 42 Maslak No: 4 İç Kapı No: 556 Sarıyer / İstanbul
Tax ID (VKN): 2111145165 (Maslak Tax Office)
Registered e-mail address (KEP): [email protected]
Contact channels:
General support: [email protected]
KVKK / privacy requests: [email protected]
Data Protection Officer (DPO): [email protected]
Legal questions: [email protected]
Phone: +90 850 309 51 26
Translation version: 3.13-en.1. Source: Turkish version 3.13.
Translation change (3.13-en.1, 1 October 2026): translation of Turkish version 3.13. The "Delete my account" item in §7.2 now also describes the path for accounts without an e-mail address (registered with a phone number): confirmation in the mobile app with a verification code sent to the registered phone and, if the account has a password, the password; an informational SMS is sent on this path. It also states that the 30-day recovery period is the same on both paths, that the deletion can be cancelled by logging in during that period, and that anyone who cannot use these paths can contact [email protected]. The statement that data subject to mandatory retention is anonymised was corrected in line with KVKK Privacy Notice §6.1: at the end of the period the account is permanently closed and profile, contact and login data are deleted or anonymised; records subject to a statutory retention obligation (such as signed contracts and signature records, payment and invoice records) are retained for the period required by law, the content of signed documents is not altered, and at the end of that period these records are also deleted or anonymised. In the §10 retention table, the legal basis of the invoicing and payment row and the free-trial row was corrected: the 10-year period arises from Turkish Commercial Code art. 82, while Tax Procedure Law art. 253 provides for 5 years; the retention period did not change. A mobile app (iOS, Android) item was added to the §1.4 list: it states that sign-in, registration and profile details, IP address and device information for the session record, and crash reports not linked to the account, used to fix app errors, are collected, and that the app does not access location, camera, contacts or the advertising identifier and does not use usage analytics tools (same as KVKK Privacy Notice §4.1). The §2 wording that described debugging as "anonymous, aggregated data" was corrected: debugging uses error and crash records, personal data is masked before sending and the records are kept for 90 days (same as KVKK Privacy Notice §3, §4.2 and §9). Error records were also kept for the web panel and the server; the purpose and the 90-day period had not been stated in earlier versions, and this version completes that missing statement. There is no new recipient or transfer abroad. This version introduces no new recipient, transfer abroad or data category; the missing statements have been completed.
Earlier translation change (3.12-en.3, 29 September 2026): wording corrections only, the Turkish text did not change. The date was aligned with the Turkish heading, the TÜBİTAK KamuSM timestamp wording (§2, §3.3, §6.1) and the first mention of KVKK were aligned with the Turkish text.