Explicit Consent
Açık Rıza Metni
Last updated: 10 September 2026
Prepared under Articles 3/1-a, 5/1 and 9 of the Turkish Personal Data Protection Law No. 6698.
This English text is provided so that the document can be read by people who do not read Turkish, including App Store reviewers. The Turkish original is the version that governs; in the event of any discrepancy, the Turkish text prevails.
1. Purpose of this text and the elements of explicit consent
This text is presented separately for the processing and transfer activities identified in the Personal Data Processing Notice that require your explicit consent in order to be carried out. Do not approve this text without reading the Notice; explicit consent is valid only if proper notice has been given beforehand.
Under Article 3 of the Turkish Personal Data Protection Law, explicit consent is consent that is (i) related to a specific subject, (ii) based on information and (iii) expressed with free will. The absence of any one of these three elements makes the consent invalid. Accordingly:
- A separate checkbox is presented for each item of consent below. No single blanket "I accept everything" box is used; that practice alone amounts to a breach of the Law.
- No item of consent is a precondition for another; each may be given or refused independently.
- Consent boxes are not presented pre-ticked (opt-out); you tick them yourself.
- You may withdraw each consent you give at any time, without giving a reason and free of charge (see Section 8).
2. The consent items at a glance
| # | Subject of consent | What happens if you do not give it? |
|---|---|---|
| 1 | Automated processing of interests to create a "persona" (profiling) | You can create your account and use the App; only the persona is not assigned and matching runs without the persona factor. |
| 2 | Processing of location data | Every function of the App that does not depend on location (sign-up, profile, matching, chat, event lists) keeps working; recommendations are simply not ranked by location. |
| 3 | Transfer of personal data abroad | Because all of the App's infrastructure is located abroad, the App cannot be used. The particular position of this item is explained in Section 5. |
| 4 | Processing of usage data through an analytics SDK | No function of the App is affected; usage statistics are simply not collected. |
| 5 | Sending commercial electronic messages for marketing and campaigns | No function of the App is affected. Core functional notifications such as "tonight is live" and "you're in" continue to be sent independently of this consent. |
3. Consent item 1 — Profiling (persona)
The interests you select when you sign up to 28 (your selections in categories such as music, nightlife, sport and culture) are used to assign you a "persona" automatically (for example "The Jazz Nomad"), and that persona is taken into account in the matching algorithm. This operation means your personal data is analysed by automated systems to create a profile specific to you — in other words, profiling.
- Only the interest categories you select are used in the persona calculation. Your chat content, your location, your device data and your messaging habits are not used.
- No decision producing legal effects concerning you or significantly affecting you is taken as a result of the persona assignment; the persona is used only to rank content and match suggestions.
- Your persona is shown to other users on your profile.
- When you withdraw this consent, your persona is erased immediately and is not recalculated.
4. Consent item 2 — Location data
We ask for access to your device's location so that we can suggest events near you, rank the lists in the "For You", "Dice", "Planned" and "Presents" sections by your location, and use proximity as a factor in the matching algorithm.
- Your location is processed only for the duration of the relevant recommendation or matching operation and is erased when it completes. No location history, route or trace is kept.
- Your location is not shared with any advertising network and is not used for marketing.
- Before a match occurs, no user can reach your precise location.
- Location permission can also be controlled at device level: Device Settings → 28 → Location.
5. Consent item 3 — Transfer of personal data abroad
Unlike the others, this item of consent is required in order for the App to be usable, and it is subject to the condition in Article 9/6-a of the Law that you be "informed of the possible risks". Do not tick this box without reading all of the risks below.
5.1 Where, to whom and why is your data transferred?
| Data transferred | Recipient | Country | Why is it necessary? |
|---|---|---|---|
| All personal data listed in Section 3 of the Notice — identity, contact, account and profile, location, match and chat content, transaction security, visual data | Google Cloud [Google Cloud EMEA Limited / Google Ireland Limited — to be confirmed from the agreement] | Ireland (European Union) | The App's server, database, authentication and file storage infrastructure runs on this provider. Without transferring your data to that infrastructure, the App cannot technically function. |
| Device notification identifier (push token) | Apple Push Notification service and/or Firebase Cloud Messaging [integration to be confirmed] | United States / Ireland | Necessary for notifications to be delivered to your device. |
| Screen views, event records, usage statistics, device identifiers | Google (Firebase Analytics) | Google's global infrastructure, including the United States | Not necessary. This transfer happens only if you separately give the analytics consent in Section 6. |
5.2 The legal position of the transfer — stated openly
Article 9 of the Law places transfers abroad under a three-tier regime: (1) an adequacy decision from the Board, (2) appropriate safeguards such as the standard contract published by the Board, (3) where neither is present and only where the transfer is incidental, explicit consent given after being informed of the possible risks.
As at the date this text was prepared:
- There is no adequacy decision issued by the Personal Data Protection Board for the country the data is transferred to.
- The data controller has not yet signed the standard contract published by the Board with the cloud service provider and has consequently not notified the Authority. Other appropriate safeguards, such as binding corporate rules or an undertaking authorised by the Board, are also not in place.
- For that reason, for the duration of the closed test, the transfer is carried out solely on the basis of your explicit consent under Article 9/6-a of the Law.
5.3 Possible risks (mandatory disclosure under Article 9/6-a)
If your data is transferred abroad in the manner described above, the possible risks you may face are as follows:
- Because there is no adequacy decision from the Board, it has not been officially established, as a matter of Turkish law, that the country your data is transferred to provides protection equivalent to that of the Law.
- Because the standard contract has not been signed, the recipient's contractual safeguards under the Law — on data security, the prohibition on onward transfer, respect for data subject rights and submission to the Board's supervision — are not in force. The transfer is subject only to the provider's own standard service and data processing terms.
- Your data may be accessed by the public authorities of the country it is transferred to (law enforcement, intelligence services, judicial bodies) under that country's own legislation; that access may be subject to rules different from the procedures and safeguards of Turkish law.
- The Personal Data Protection Board's supervisory and enforcement powers are limited in practice over a recipient established abroad.
- Exercising your rights, or claiming compensation in the event of a breach, may have to be pursued in a foreign country and under foreign law, so it may take longer, cost more, and effective legal remedies may become harder to reach in practice.
- The recipient may transfer your data to sub-processors in other countries within its own service chain (onward transfer); the risks above then apply to those countries as well.
- Detecting a data breach that occurs abroad, notifying it to the data controller and passing it on to you may all be delayed.
5.4 An honest word on the "free will" element of consent
Under the Law, explicit consent is valid only if it is given freely. Where the provision of a service is made conditional on giving explicit consent, the consent cannot be said to have been given freely. We think it right to point to this principle transparently:
- Because all of the App's server infrastructure is located abroad, it is technically impossible for you to use the App if you do not give this consent. That has the appearance of making the service conditional on consent.
- To keep that appearance to a minimum: (i) the current stage is not a public service but a closed test in which participation is entirely voluntary and by invitation, so there is no service or right you lose by leaving it, and (ii) this arrangement is temporary and will end under the undertaking below.
Before the App is released publicly, the standard contract published by the Board (the controller-to-processor-abroad module) will be signed with the cloud service provider and notified to the Authority within five business days of signature. Once that safeguard is in force, the transfer will rest on an appropriate safeguard under Article 9/4-c, so the practice of obtaining explicit consent for the transfer abroad will end and this checkbox will be removed from the sign-up flow. Users will be informed separately inside the App about that change.
6. Consent item 4 — Analytics SDK
We would like to use a third-party software development kit (SDK) called Firebase Analytics in order to measure how you use the App (which screens you view, which functions you use, how long your sessions last) and to improve service quality.
- The data collected through this SDK is screen views, event records, session information and device identifiers. Your chat content and your location data are not transferred to this SDK.
- The data is processed on Google's infrastructure abroad (including the United States); this consent therefore also covers the transfer of that data abroad, and the risks listed in 5.3 apply to that transfer as well.
- Not giving, or withdrawing, this consent does not affect any function of the App.
If an advertising measurement SDK (for example Meta SDK, AppsFlyer, TikTok SDK) is added to the App in future, a separate consent box must be presented for it; the current analytics consent does not cover advertising SDKs. On iOS, access to the advertising identifier also requires Apple's App Tracking Transparency system permission, and that permission does not replace explicit consent under the Law. As at the date of this text there is no advertising measurement SDK in the App, so no such box appears.
7. Consent item 5 — Marketing and commercial electronic messages
We ask whether you wish to receive messages containing campaigns, recommendations, discounts and new feature announcements by SMS, email or marketing push notification.
- This preference is subject to two separate bodies of legislation: the Personal Data Protection Law (explicit consent) as regards the processing of your contact details for that purpose; and Law No. 6563 on the Regulation of Electronic Commerce and the Regulation on Commercial Communication and Commercial Electronic Messages (consent) as regards the sending of the message.
- Your consent is recorded in the Ministry of Trade's Message Management System (İYS). You can view your consent and opt out at brand level through İYS.
- Notifications belonging to the App's core function, such as "tonight is live" and "you're in", are not commercial electronic messages; they continue to be sent independently of this consent.
- You may withdraw your consent at any time, without giving a reason and free of charge; your opt-out is actioned within three business days.
8. Withdrawing consent
You may withdraw each explicit consent you have given at any time, without giving a reason and free of charge. Withdrawal takes effect prospectively; processing lawfully carried out while the consent was in force remains valid.
| Consent | Where it is withdrawn | Effect of withdrawal |
|---|---|---|
| Persona (profiling) | Settings → Privacy → Persona Preference | The persona is erased immediately; matching continues to run without the persona factor. |
| Location | Settings → Privacy → Location · Device Settings → 28 → Location | Location is no longer processed; functions that do not depend on location are unaffected. |
| Transfer abroad | Settings → Privacy → Transfer Abroad | The App becomes technically unusable; the account is closed and the data erased within the periods in Section 9 of the Notice. |
| Analytics SDK | Settings → Privacy → Data and Analytics Preferences | Collection of analytics data stops; App functions are unaffected. |
| Marketing messages | Settings → Notifications → Marketing Messages · the opt-out link in every message · iys.org.tr | The opt-out is actioned within three business days at the latest; no commercial electronic message is sent afterwards. |
The Settings → Privacy screen shows the current state (on/off) of each of the consents above separately, and each can be withdrawn with a single tap. Offering a bulk "turn off all permissions" option does not remove the requirement that each consent also be switchable off on its own.
9. Keeping consent records
The burden of proving that explicit consent was obtained falls on the data controller. For each item of consent we therefore record separately: the date and time the consent was given or withdrawn (timestamp), the version of the consent text, and the screen and device on which the approval was given. Consent records are kept, after the consent ceases to be valid, within the periods in Section 9 of the Notice.
10. Declaration
Each of the consents above is independent of the others. Not giving a consent, or withdrawing it later, does not prevent me from using the core functions of the App, save for the case expressly stated in Section 5. I declare and accept that I have read the Personal Data Processing Notice, that I have been informed of the explanations and possible risks it contains, and that I have given the consents I have ticked above of my own free will.
Presented together with the Personal Data Processing Notice and is not valid without it.
Last updated: 10 September 2026