Privacy Notice under the Turkish Data Protection Law (KVKK) and Privacy Policy

Türkçe

Service provider / data controller for the relevant activities: CREART LLC ("Firevibe")

Address: 364 E MAIN ST STE 1001, MIDDLETOWN, DELAWARE, USA

Support, complaints, cancellation/refund and personal data applications: help@firevibe.ai

Website: https://firevibe.ai

Part A. Notice under the KVKK

1. Scope and roles

This notice informs visitors of firevibe.ai, account holders, purchasers, people invited to a project, people who contact us for support and, where necessary, legal representatives about their personal data. Your data is processed by the data controller identified above for the purposes below. This notice is not a consent text; a record that you have been informed does not mean that you have permitted every processing operation.

Where data about the visitors or customers of a website or application created by the user is processed on behalf of and on the instructions of the relevant customer, the customer acts as the data controller and Firevibe as the data processor. The customer operating such a site provides its own notice. The account, payment or security operations Firevibe carries out for its own purposes are assessed separately; roles are not determined solely by the name given in the contract.

2. Data sources and processing methods

Data is collected electronically through registration and payment forms, account settings, the project editor, file uploads, AI prompts, support correspondence, APIs and integrations, system logs and, depending on your preferences, cookies or similar technologies. If a request or an explanation of a transaction is submitted by a representative, the necessary representation and contact information may be processed, limited to that transaction. Necessary records such as transaction status may be received from Stripe and from connection providers.

3. Purposes and legal bases

The explanations below are limited to the scope of data necessary for the relevant operation.

Data / operationPurposeLegal basis under the KVKK
Name, account email, account/session identifier and access informationAccount creation, session and account managementArticle 5(2)(c): necessity for the conclusion or performance of a contract
The email address of a person invited to a project and the invitation statusDelivering the project invitation and matching it with an account when the invitation is acceptedArticle 5(2)(f)
Order, plan, credit movements, payment status and necessary invoice informationPurchase, pricing and credit accountingArticle 5(2)(c); Article 5(2)(a) or (ç) for applicable invoicing/record-keeping obligations; Article 5(2)(e) for dispute records
Prompts, project content and the account holder's data within uploaded filesThe requested generation, editing, storage and publishingArticle 5(2)(c) to the extent directly related to and necessary for the operation; for third-party data, the special explanation below
Support correspondence and issue recordsSupport, request and complaint resolutionArticle 5(2)(c) for service support; Article 5(2)(e) for establishing and protecting rights
IP, time, session, error and security event logsEnsuring security, detecting misuse and errorsArticle 5(2)(f) to a necessary and balanced extent; Article 5(2)(a)/(ç) where a concrete statutory record-keeping obligation exists; Article 5(2)(e) for protecting rights
Parent/guardian contact, representation authority and consent information, where provided in a relevant application or transactionAssessing the representation conditions of the relevant application or transactionArticle 5(2)(c)/(ç) and, for evidence, (e), according to the concrete representation or contract process; operations requiring separate consent are handled separately
Analytics identifiers, browsing and usage eventsAnalytics with PostHogExplicit consent under Article 5(1) for non-essential tracking; limited to the scope in the cookie notice
Advertising identifiers and conversion eventsAdvertising measurement with Meta Pixel and Google advertising tools; retargeting depending on the features usedExplicit consent under Article 5(1)
The referral identifier of a visitor arriving through an affiliate link; the email address if that visitor signs upMeasuring affiliate program referrals with Tolt and calculating the partner's commissionExplicit consent under Article 5(1)
Email, marketing preference and consent recordCampaign emailsSeparate explicit consent under Article 5(1) for processing data for marketing purposes; additionally, consent under Law No. 6563 for sending messages; Article 5(2)(ç)/(e) for proving consent or refusal

Uploading a file does not automatically create a legal basis for the data of third parties within it. For data processed on behalf of a customer, the customer determines the legal basis and provides the necessary notices and permissions; Firevibe retains its own obligations. Use cases involving health, biometric and other special categories of personal data may be carried out only where the relevant processing condition under Article 6 of the KVKK and the necessary additional security measures are in place. The customer meets these conditions for the operations under its own data controllership; Firevibe fulfils the obligations arising from its own role. Accepting the contract or uploading a file does not replace the data subjects' explicit consent. An operation whose conditions are not met may not be started or continued.

4. Recipients and purposes of transfer

  • Infrastructure and hosting service providers: hosting and storage of servers, databases, files and published projects.
  • AI service providers: processing of the prompts and content needed for the AI function used. Not every file is sent automatically to all providers.
  • Payment service provider (Stripe): payment operations and the handling of charges and refunds.
  • Analytics, advertising measurement and affiliate program services: analytics events depending on your preference, and advertising, conversion and referral measurement.
  • Error monitoring service providers: the technical records needed to detect and fix errors.
  • Competent public authorities, courts and necessary professional advisers: operations limited to legal obligations and the protection of rights.
  • Communication and support infrastructure providers: the communication and message data needed to deliver service notifications, support requests and, with the necessary permission, campaign emails.

Whether a service provider acts as a data processor or an independent data controller is determined according to the relevant operation and contract. A supplier's name is not an authorization for every kind of sharing. Published content is made available to site visitors within the visibility scope the user sets.

5. International transfers

Because of the US company and the foreign infrastructure and AI services, international data flows may exist. These flows must be carried out under the applicable conditions of Article 9 of the KVKK. Accepting the contract or uploading a file does not by itself make a regular international transfer lawful.

The use of infrastructure and hosting, AI, payment, analytics, advertising measurement, affiliate program, communication and error monitoring services may result in the personal data the relevant function requires being processed by recipients abroad. The scope of data that may be transferred is limited to the data and recipient categories above. The processing countries depend on the contractual and technical configuration of the service used; this notice does not guarantee exclusive storage in a particular country.

An applicable adequacy decision or an appropriate safeguard provided for in Article 9 of the KVKK must exist for an international transfer; where these are absent, processing may take place only under the limited and occasional transfer conditions in the law. Regular cloud and AI use is not based on a general acceptance of the contract or on the occasional transfer exception. This explanation is not a declaration that the necessary transfer agreement has been signed or the notifications completed. Data subjects may request recipient and transfer information through the application channel; the right to request does not remove Firevibe's obligation to inform in advance.

6. Retention and deletion

The user may permanently delete their account and projects from the interface. The stopping of publication because the plan has ended does not by itself delete the project or the database. Content kept for the active service and the payment, contract and dispute records that must be kept by law are separated from each other. Personal data with no legal retention ground is deleted, destroyed or anonymized once the grounds cease.

Account and project data is kept for as long as it is necessary to operate the service. When the user carries out a deletion, the relevant active content enters the permanent removal process; the stopping of publication does not by itself count as a deletion instruction. Data whose processing ground has ceased is removed under the applicable deletion, destruction or anonymization rules. Technical backups, security logs and copies at external services are subject to life cycles separate from the active content; it is not undertaken that all copies are deleted at the same time. In determining the retention period, the necessity of the service, security, applicable statutory record-keeping obligations and the concrete need in a dispute are taken as the basis. A backup or security ground does not authorize indefinite retention.

Payment, invoice, contract and consent records are kept limited to the applicable statutory periods. For the relevant information and documents concerning distance transactions, a record-keeping obligation of at least three years is observed; special periods applying to different kinds of records are reserved. Data kept for the protection of rights is limited to the necessary scope, its access is restricted, and it is not used for any other purpose.

7. Rights and applications

Under Article 11 of the KVKK you have the right to learn whether your data is processed; to request information if it has been processed; to learn the purpose of processing and whether it is used in accordance with that purpose; to know the recipients in Turkey and abroad; to request the correction of incomplete or incorrect data; to request deletion or destruction where the conditions are met, and to request that these operations be notified to the recipients; to object to a result against you arising exclusively from automated analysis; and to claim compensation for damage caused by unlawful processing.

You may submit your application in writing to CREART LLC, 364 E MAIN ST STE 1001, MIDDLETOWN, DELAWARE, USA. Other application methods provided for in the legislation are reserved. You may use the help@firevibe.ai channel from the email address you previously provided and which is registered in the system. Identity verification is carried out proportionately; unnecessary identity documents are not requested. The application elements required by the Communiqué are provided.

Requests are answered as soon as possible and within thirty days at the latest. The process is free of charge as a rule; the cases in which the legislation permits a fee are reserved. For a complaint to the Board, a prior application to the data controller and the related periods apply. Inalienable rights arising in foreign countries are also protected.

Part B. Confidentiality Commitments

Firevibe does not use customer files and project content to train or improve its own AI models; processing is limited to the function requested by the user and the provision of the service. The retention and training terms of third-party AI services depend on the API product, contract and settings used; Firevibe's own commitment not to use data for training may not be interpreted as an unverified third-party guarantee.

The necessary technical and administrative security measures are taken; no guarantee is given of an encryption standard, a certificate or inaccessibility that is not applied. API secret values must be entered only in the dedicated area; the agent uses the key's name; the secret value is not shown directly to the agent and is processed in authorized system components for the connection to work. The application authorizations under the users' own control are their own responsibility; Firevibe's own security obligations continue.

In transactions by users under 18, the legally required parent or guardian consent and representation conditions apply. Firevibe does not collect a separate parent or guardian consent form; this does not mean that the legally required consent exists. Acceptance of the terms of use does not replace marketing permission or permission for non-essential tracking. Additional applicable conditions and data minimization are observed for children's data.

In the event of changes, the current date and version are shown; the necessary information and, where applicable, new consent are provided for a new purpose. Publishing a new policy does not create a permission that was not given in the past.

Part C. Additional Information under the GDPR

This part applies where Regulation (EU) 2016/679, the General Data Protection Regulation of the European Union (the GDPR), applies to the relevant data processing activity. The GDPR may apply in particular to processing in the context of offering goods or services to persons within the European Union/European Economic Area or of monitoring the behaviour of such persons. The mere fact that the website can be accessed from these countries does not by itself mean that the GDPR applies.

The data categories, collection sources, processing purposes, recipient groups and retention criteria explained in Part A also apply to processing within the scope of the GDPR. In such processing, the legal basis may, depending on the processing activity, be consent under Article 6(1)(a) of the GDPR, the conclusion or performance of a contract under Article 6(1)(b), a legal obligation under Article 6(1)(c) or a legitimate interest under Article 6(1)(f). Legitimate interest is relied on for the purposes of platform and account security, the prevention of misuse, the technical improvement of the service and the establishment, exercise or defence of legal claims, balanced against the rights and freedoms of the data subject. Consent may be withdrawn; withdrawal does not affect the lawfulness of the processing carried out before it.

Health data, biometric data and other special categories of personal data are processed only where one of the conditions set out in Article 9 of the GDPR is met. Non-essential analytics, advertising and similar tracking activities are subject to the preference or consent mechanisms required under the applicable cookie and electronic communications rules. Where the visitor/customer data of a site or application created by the customer is processed solely on the customer's instructions, the customer is the controller and Firevibe is the processor; this relationship is governed by a separate data processing agreement in accordance with Article 28 of the GDPR.

Where personal data is transferred outside the EU/EEA, the conditions in Article 44 et seq. of the GDPR apply. Depending on the processing concerned, the transfer is based on a valid adequacy decision or on appropriate safeguards under Article 46 of the GDPR, including the European Commission's standard contractual clauses and, where necessary, supplementary measures. The derogations in Article 49 of the GDPR are used only in the limited cases provided for by law. Information on the transfer mechanism applied may be requested at help@firevibe.ai.

Subject to the conditions in Articles 15 to 22 of the GDPR, data subjects have the right to access their data, to have inaccurate data rectified, to request the erasure of their data or the restriction of processing, to data portability, to object to processing and to direct marketing, to withdraw consent, and not to be subject to a decision based solely on automated processing which produces legal or similarly significant effects. Requests may be directed to help@firevibe.ai and are, as a rule, answered within one month; where the complexity and number of the requests so require, the period may be extended by a further two months, with the reason communicated within the first month.

Data subjects may also lodge a complaint with the competent data protection supervisory authority in the EU/EEA country of their habitual residence, their place of work or the place of the alleged infringement. Should an obligation arise to designate a representative in the EU under Article 27 of the GDPR or a data protection officer under Article 37, their contact details will be published in this notice.

Where an information society service is offered directly to a child and the processing is based on consent, Article 8 of the GDPR and the age limit under the law of the relevant Member State apply. If a new processing purpose arises, the additional information required by the GDPR is provided before the processing begins and, where necessary, new consent is obtained.

Convenience translation of the Turkish document. The Turkish text prevails. Read the original