Personal Data Processing Notice
KVKK Aydınlatma Metni
Last updated: 10 September 2026
Prepared under Article 10 of the Turkish Personal Data Protection Law No. 6698 and the Communiqué on the Principles and Procedures to be Followed in Fulfilling the Obligation to Inform.
This English text is provided so that the document can be read by people who do not read Turkish, including App Store reviewers. The Turkish original is the version that governs; in the event of any discrepancy, the Turkish text prevails.
1. Identity of the data controller
Under the Turkish Personal Data Protection Law No. 6698 (the "Law"), your personal data is processed by the natural person (sole proprietor) whose details appear below, acting as data controller, within the 28 Social mobile application operated under the "28" brand (the "App" or "28").
| Name and surname of the data controller | |
| Legal status | Natural person trader / sole proprietorship (no legal entity) |
| Business name / brand | 28 — the "28 Social" mobile application |
| Turkish national ID number | |
| Business (service) address | |
| Tax office / tax number | |
| Trade registry office / registry number | (to be completed if registered as a trader) |
| MERSİS number | (if registered) |
| Telephone | |
| General email address | hello@28istanbul.com |
| Data protection request address | kvkk@28istanbul.com |
| Registered electronic mail (KEP) | (if any) |
| Data controllers' registry (VERBİS) status | Assessed as falling within the exemption from the registration obligation — see Section 14 |
2. Scope of this notice and the TestFlight stage
This notice explains, for the natural persons who download, register for and use the App ("User", "data subject", "you"), the categories of personal data processed, the methods and purposes of processing and the legal grounds relied on; who the data is transferred to; how long it is stored; and your rights under Article 11 of the Law.
The App is currently in a closed test (beta) run through Apple TestFlight. At this stage the App is open to a limited number of invited test users; there is no public store release. Participation in the test is entirely voluntary and you may leave the test at any time. Matters specific to the test stage are indicated separately in the text.
This notice forms a whole together with the Explicit Consent text, the Terms of Use, the Privacy Policy, the Cookie and SDK Policy and the Commercial Electronic Message Consent. The duty to give notice and the duty to obtain explicit consent are two independent obligations; the fact that you have given consent does not remove the requirement to give notice.
3. Categories of personal data processed and collection methods
The personal data processed within the App, its categories and the methods by which it is collected are shown in the table below. No category of personal data outside this table is processed.
| Data category | Personal data processed | Collection method |
|---|---|---|
| Identity data | First name, surname, date of birth (solely to verify the age of 18; the profile shows only the age as a number, never the date) | By the User completing the sign-up form, by non-automated means, directly from the data subject |
| Contact data | Email address, mobile phone number | By the User completing the sign-up and settings screens, by non-automated means, directly from the data subject |
| Account and profile data | Username, profile photo, age, gender, interest selections, the "persona" calculated by the App, the free text written by the User in the "about me" field | By declaration through the interest and profile screens (non-automated); the persona calculation is made by the App by automated means |
| Location data | The device's current or approximate location (no location history or route is kept) | Through the device's location services, only where permission is granted, by automated means |
| User transaction data | Match records, chat (messaging) content, events attended or shown interest in, in-app interactions (actions in the For You, Dice, Planned and Presents sections) | During the User's in-app interactions, by automated means |
| Transaction security data | IP address, device type and model, operating system and version, app version, session and sign-in/sign-out (log) records, the hashed form of the password | During the communication between the device and the servers, by automated means |
| Marketing data | Notification preferences, commercial electronic message consent and opt-out records, campaign notification interaction data (only where the relevant explicit consent is given) | By declaration through the notification preference screen; interaction data by automated means |
| Analytics and usage data | Screen views, event records, session duration, in-app usage statistics, device identifiers (only where the relevant explicit consent is given — see the Cookie and SDK Policy) | Through the Firebase Analytics software development kit (SDK), by automated means |
| Request, complaint and moderation data | In-app "Report" and "Block" records, the content and chat records subject to a report, support correspondence | Upon the User's report, partly by non-automated means |
| Visual data | Profile photo and content images uploaded by the User | By the User uploading them, by non-automated means |
The App has no paid features and no in-app purchases. No financial or payment data is therefore processed, and that category has been deliberately left out of this text. If a paid feature is added in future, this section and the retention section must be updated and Users informed separately before any such processing begins.
4. Purposes of processing and legal grounds
Under Article 5 of the Communiqué on the Principles and Procedures to be Followed in Fulfilling the Obligation to Inform, and the settled decisions of the Personal Data Protection Board, the purposes of processing may not be listed generally with the legal grounds stated separately and in general terms. For that reason the purpose and the legal ground are matched separately for each group of data below.
| Personal data | Purposes of processing | Legal ground (Art. 5) |
|---|---|---|
| First name, surname, date of birth, email, mobile number, username, hashed password | Creating the membership record and managing the account; contacting the User; ensuring account security; enforcing the age limit of 18 | Directly related to the conclusion or performance of a contract (Art. 5/2-c). For the age check additionally: necessary for the controller to fulfil a legal obligation (Art. 5/2-ç) |
| Profile photo, username, age, gender, interest selections, "about me" free text | Creating the profile and showing it to other users to the extent the User chooses | Directly related to the conclusion or performance of a contract (Art. 5/2-c) |
| Interest selections → "persona" assignment | Analysing the interest selections by automated systems to assign the User a "persona" (personality profile) and using that persona in the matching algorithm | Explicit consent (Art. 5/1). Since this activity amounts to automated profiling, it is deliberately not based on performance of a contract or on legitimate interest |
| Match records, chat content, event participation data, in-app interactions | Running the matching algorithm at set time windows; opening the chat room when a match occurs and delivering and storing messages; managing event lists and attendance | Directly related to the conclusion or performance of a contract (Art. 5/2-c) — this is the core function of the App |
| Location data | Showing the User nearby events and user recommendations; using proximity as a factor in the matching algorithm | Explicit consent (Art. 5/1). Location is not necessary for the App's core functions and is therefore processed solely on the basis of consent |
| IP address, device data, session and log records | Ensuring the security of the App and of accounts; detecting and preventing fake accounts, bots and abuse; resolving technical faults | Necessary for the legitimate interests of the controller (Art. 5/2-f). For record-keeping under Law No. 5651 additionally: expressly provided for by law (Art. 5/2-a) |
| Report and moderation records (reported profile, content and chat records), support correspondence | Reviewing reports of bullying, harassment, threats and similar breaches; keeping users safe; following up requests and complaints; producing evidence in legal disputes | Necessary for the establishment, exercise or protection of a right (Art. 5/2-e); necessary for the legitimate interests of the controller (Art. 5/2-f) |
| Notification preferences; email and mobile number (for marketing) | Sending commercial electronic messages announcing campaigns, promotions and new features | Explicit consent (Art. 5/1). Additionally, the separate consent obtained under Law No. 6563 and the Regulation on Commercial Communication and Commercial Electronic Messages |
| Analytics and usage data (Firebase Analytics) | Measuring the App's usage statistics, detecting errors and performance problems, improving service quality | Explicit consent (Art. 5/1) — see the Cookie and SDK Policy |
| Data already collected in the categories listed above | Meeting the lawful requests of courts, prosecutors, law enforcement, the Personal Data Protection Authority and other competent administrative bodies | Expressly provided for by law (Art. 5/2-a); necessary for the controller to fulfil a legal obligation (Art. 5/2-ç) |
The distinction between functional (mandatory) notifications and marketing notifications: notifications belonging to the App's core function, such as "tonight is live" or "you're in", are not commercial electronic messages. They are sent as part of performing the contract and are not subject to separate consent. Notifications containing campaigns, discounts and promotions are, as stated above, subject to separate explicit consent and to separate consent under Law No. 6563.
5. Special categories of personal data
28 does not knowingly and systematically collect the special categories of personal data listed in Article 6/1 of the Law (race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, biometric and genetic data). There is no mandatory field in the sign-up flow that asks for such data.
That said, the App's free text fields (the profile "about me" section, shared content, comments) and its chat infrastructure are technically capable of carrying special category data that a User chooses to share. In that case the following distinction applies:
- Special category data you make public of your own volition in your profile or in your public posts: this data is processed under Article 6/3-ç of the Law — "relating to personal data made public by the data subject and consistent with their intention to make it public" — only to the extent covered by that intention (your profile being viewed and your content being published). It is not used for marketing, for profiling or in the matching algorithm.
- Data you share within chat (messaging) content: chats are not treated as having been made public. This content is processed solely to deliver the message to its recipient and to store it, as part of performing the contract; it is not read, analysed, profiled or used for advertising by us.
- Moderation review following a report: where a chat or a piece of content is reported for bullying or harassment, the records concerned may be viewed solely for the purpose of the review and only by a limited number of authorised staff. Where special category data is present, the processing rests on Article 6/3-d, "necessary for the establishment, exercise or protection of a right".
Adequate measures determined by the Board under Article 6/4 of the Law are taken when processing special categories of personal data. We strongly advise our Users not to publish information such as their health status, religious belief or political views in their profile or in the content they share.
6. Transfers within Türkiye
Your personal data may be transferred within Türkiye under Article 8 of the Law, limited strictly to the recipient groups, purposes and legal grounds set out below.
| Personal data transferred | Recipient group | Purpose of transfer | Legal ground |
|---|---|---|---|
| The information you choose to show on your profile: username, profile photo, age, persona, shared interests; chat content after a match | Other Users you have matched with | Providing the matching service and enabling the chat | Performance of a contract (Art. 5/2-c and Art. 8/2-a) |
| Name, surname, contact details, reported content and chat records, documents relating to a dispute | Lawyers, financial advisers and similar advisers engaged | Obtaining legal and financial advice, conducting legal matters | Legal obligation of the controller (Art. 5/2-ç); establishment or protection of a right (Art. 5/2-e); legitimate interest (Art. 5/2-f) |
| All data requested and falling within the scope of a lawful request | Competent public institutions and bodies; courts, prosecutors and law enforcement; the Personal Data Protection Authority | Meeting statutory obligations and the requests of competent authorities | Expressly provided for by law (Art. 5/2-a); legal obligation of the controller (Art. 5/2-ç) |
Before a match occurs, no User can reach your contact details, your date of birth or your precise location. Your data is not transferred commercially to, or sold to, advertising networks, data brokers or any third party not listed in this table.
7. Transfers abroad
The App's server, database and file storage infrastructure runs on a cloud service provider established outside Türkiye. The personal data listed in Section 3 is therefore necessarily transferred abroad in order for you to be able to use the App. Transparency requires this to be stated openly.
| Personal data transferred | Recipient (processor) | Country / region | Purpose of transfer |
|---|---|---|---|
| All personal data listed in Section 3 (identity, contact, account and profile, location, user transaction data — including chat content —, transaction security, visual data) | Google Cloud — [Google Cloud EMEA Limited / Google Ireland Limited: to be confirmed from the agreement] | Ireland (European Union) — [hosting region to be confirmed from the console settings] | Providing the server, database, authentication and file storage infrastructure the App needs in order to run |
| Device notification identifier (push token) and the minimum data needed to deliver a notification | Push notification infrastructure provider — Apple Push Notification service (APNs) and/or Firebase Cloud Messaging (FCM) [integration to be confirmed] | United States / Ireland | Delivering App notifications to your device |
| Screen views, event records, session and usage statistics, device identifiers | Google (Firebase Analytics) | Google's global infrastructure, including the United States | Measuring usage statistics and improving service quality — only where explicit consent is given |
7.1 Legal basis for the transfer abroad, and our current position
Article 9 of the Law was amended by Law No. 7499, which entered into force on 12 March 2024, and transfers abroad were placed under a three-tier regime:
- Adequacy decision (Art. 9/1): a transfer may be made where the Board has issued an adequacy decision for the country, sector or international organisation concerned.
- Appropriate safeguards (Art. 9/4): where there is no adequacy decision, a transfer may be made if one of the following safeguards is in place between the parties: (a) an agreement that is not an international treaty, together with the Board's authorisation, (b) binding corporate rules approved by the Board, (c) the standard contract published by the Board, or (ç) a written undertaking providing adequate protection, together with the Board's authorisation. The standard contract must be notified to the Authority within five business days of signature (Art. 9/5).
- Incidental cases (Art. 9/6): where there is no adequacy decision and none of the appropriate safeguards can be provided, a transfer may be made — only where it is incidental — in the limited circumstances set out in that article, including where the data subject gives explicit consent to the transfer having been informed of the possible risks.
As at the date this text was prepared, the data controller has not yet provided any of the appropriate safeguards in tier 2 above; the standard contract published by the Board has not been signed and consequently has not been notified to the Authority. For the duration of the TestFlight closed test, the transfer abroad is therefore carried out under Article 9/6-a of the Law, on the basis of the explicit consent you give having been informed of the possible risks. The risks the transfer rests on and the scope of that consent are set out in detail in Section 5 of the Explicit Consent text.
The circumstances in Article 9/6 are provided only for incidental (exceptional, non-continuous) transfers. Continuous and systematic data hosting on a cloud infrastructure is, as a rule, not incidental. The data controller therefore undertakes, before the App is released publicly, to sign the standard contract published by the Board with the cloud service provider (the controller-to-processor module) and to notify the Authority within five business days of signature. Once that safeguard is in place, this section will be updated and the practice of obtaining separate explicit consent for the transfer abroad will end.
8. Automated decision-making and profiling
The App analyses the interests you select during sign-up by automated systems, assigns you a "persona" (for example "The Jazz Nomad") and uses that persona in the matching algorithm. This activity amounts to profiling and is carried out solely on the basis of your explicit consent.
- The persona is calculated only from the interest categories you select; your chat content, your location and your device data are not used in the calculation.
- No decision producing legal effects concerning you or significantly affecting you (such as closing your account or depriving you of a service) is taken as a result of the persona assignment; it is used only to rank content and match suggestions.
- Under Article 11/1-g of the Law you have the right to object to an outcome against you arising from the analysis of your data solely by automated means.
- If you do not give, or you withdraw, persona consent, your account is still created and can still be used; only the persona is not assigned and matching runs without the persona factor.
9. Retention periods and destruction
Retention periods are set on the following principle: for each category of data we first look at whether the relevant legislation (tax law, commercial law, e-commerce legislation, Law No. 5651) prescribes a statutory retention or limitation period; if there is such a period, it governs. Where no statutory period is prescribed, the data is kept only for as long as the purpose of processing requires and is then erased, destroyed or anonymised (Articles 4/2-d and 7 of the Law).
| Data category | Retention period | Basis for the period |
|---|---|---|
| Account, identity and contact data | For as long as the account is active. After the account is deleted: 6 months | No statutory retention period applies. The period after deletion is set, with regard to the principle of proportionality, so that the data can serve as evidence in any objection, complaint or legal claim. While the ten-year general limitation period in Article 146 of the Turkish Code of Obligations is the upper bound, that period was found disproportionate given data minimisation and the period was kept short. |
| Persona, interest selections | For as long as the account is active; erased immediately if consent is withdrawn | Processing based on explicit consent. Withdrawal removes the ground for processing (Art. 7/1) |
| Match records and chat content | For as long as the account is active. After the account is deleted or the chat is mutually ended: 30 days | No statutory retention period applies. The additional 30 days is provided so that any safety or abuse report made in that window can be reviewed |
| Location data | Not stored. Processed only for the duration of the relevant recommendation or matching operation and erased when it completes | The principle of being connected with, limited to and proportionate to the purpose (Art. 4/2-ç). No location history, route or trace is kept |
| Transaction security data (IP, device, log records) | 1 year | The traffic data retention period prescribed for hosting providers under Law No. 5651 and the related regulation (minimum 1 year). Whether the App qualifies as a hosting provider is a matter of legal assessment; the minimum period has been adopted as a precaution |
| Report, moderation and dispute records | 2 years (or, where a dispute is ongoing, until it is finally resolved) | The two-year limitation period under Article 72 of the Turkish Code of Obligations for tort claims, running from the date the damage and the tortfeasor become known. These records may be kept even if the user concerned has deleted their account |
| Commercial electronic message consent and opt-out records | 3 years from the date the consent ceases to be valid | Article 13/2 of the Regulation on Commercial Communication and Commercial Electronic Messages |
| Commercial electronic message content records | 3 years from the date of record | Article 13/2 of the Regulation on Commercial Communication and Commercial Electronic Messages |
| Analytics and usage data (Firebase Analytics) | 14 months (this period must be set in the SDK console) | No statutory retention period applies; the period required by the purpose of the analysis governs. Collection stops when consent is withdrawn |
| Records of requests and responses under Article 11 | 3 years from the conclusion of the request | Proof that the duty to inform and to respond to requests has been met (Art. 13); the complaint periods before the Board (Art. 14) have been taken into account |
Once a retention period expires, the personal data is erased, destroyed or anonymised at the latest in the first periodic destruction cycle that follows (at intervals of no more than six months). Deletions carried out at your request are concluded within 30 days at the latest, under Articles 7 and 13 of the Law.
10. Data security measures
Under Article 12 of the Law, technical and administrative measures are taken to provide an appropriate level of security, in order to prevent the unlawful processing of and unlawful access to your personal data and to ensure its safekeeping:
Technical measures
- All communication between the device and the servers takes place over an encrypted connection (TLS).
- Passwords are not stored in plain text; only their irreversibly hashed form is kept.
- Access rules are applied at database level: a User can reach only their own records and the chat and event data for which a mutual match has been established.
- An authorisation matrix is applied; access to chat and report records is limited to moderation review and is logged.
- Backups are taken and kept encrypted.
- The security configurations offered by the cloud service provider (authentication, access rules, audit logs) are used actively.
Administrative measures
- Data processing agreements are concluded with processors (cloud and notification service providers).
- Confidentiality undertakings are signed with everyone who has access to personal data.
- A personal data inventory and a retention and destruction policy are maintained and kept up to date.
- An incident response procedure for data breaches is prepared. Under Article 12/5 of the Law and the relevant Board decision, a breach is notified to the Board without delay and within 72 hours at the latest of becoming known, and to the affected data subjects as soon as reasonably possible.
Despite all the measures taken, we remind you that no transmission of data over the internet and no electronic storage is 100% secure.
11. Age limit of 18 and children's data
28 is intended only for people who have completed the age of 18 and does not knowingly collect personal data from anyone under 18. The date of birth declared at sign-up is checked both in the app interface and on the server side; if a date of birth under 18 is entered, no account is created. If an account is reported as belonging to someone assessed to be under 18, the account is suspended and the data concerned is erased without delay.
12. Your rights under Article 11 and how to apply
Under Article 11 of the Law you have the right, by applying to the data controller, to:
- learn whether your personal data is being processed,
- request information if your personal data has been processed,
- learn the purpose of processing and whether the data is used in line with that purpose,
- know the third parties within Türkiye or abroad to whom your personal data has been transferred,
- request the correction of your personal data if it has been processed incompletely or inaccurately,
- request the erasure or destruction of your personal data within the conditions set out in Article 7,
- request that correction, erasure and destruction be notified to the third parties to whom your personal data has been transferred,
- object to an outcome against you arising from the analysis of your data solely by automated means,
- claim compensation for damage suffered because your personal data has been processed unlawfully.
12.1 Where you can exercise these rights directly inside the app
| Request | In-app path |
|---|---|
| Access to your data and information request | Settings → Privacy → My Data |
| Deleting the account and all data | Settings → Delete My Account |
| Withdrawing persona (profiling) consent | Settings → Privacy → Persona Preference |
| Withdrawing location consent | Settings → Privacy → Location · also: Device Settings → 28 → Location |
| Withdrawing marketing message consent | Settings → Notifications → Marketing Messages · also: brand-level opt-out at iys.org.tr |
| Withdrawing analytics SDK consent | Settings → Privacy → Data and Analytics Preferences |
| Withdrawing consent to transfer abroad | Settings → Privacy → Transfer Abroad — see the warning below |
Because all of the App's server infrastructure is located abroad, if you withdraw your consent to the transfer abroad it becomes technically impossible for you to continue using the App. In that case your account is closed and your data is erased within the periods in Section 9. This is a limitation you need to know about before you give consent, and it is explained separately in Section 5 of the Explicit Consent text.
12.2 How to apply
In line with the Communiqué on the Principles and Procedures for Applications to the Data Controller, you may submit your requests together with information verifying your identity: in writing to , to the registered electronic mail address , from the email address registered in our system to kvkk@28istanbul.com, or through the in-app "Settings → Privacy → Data Request" section.
- Your application is concluded as soon as possible depending on its nature and in any event within thirty days at the latest (Art. 13/2).
- Applications are concluded free of charge as a rule. Where the process requires an additional cost, the fee in the tariff set by the Personal Data Protection Board may be charged (Art. 13/2).
- If your application is refused, if you find the response inadequate or if no response is given within the period, you may complain to the Personal Data Protection Board within thirty days of learning the response and in any event within sixty days of the date of application (Art. 14). Applying to the data controller first is a mandatory step before complaining to the Board.
13. Change of purpose, proof of notice and updates
If your personal data needs to be processed for a purpose other than those stated in this text, a separate notice is given for that new purpose before the processing begins. This rule applies even where the new purpose is an extension of a purpose already notified.
The burden of proving that the duty to inform has been met falls on the data controller. For that reason, the fact that this text was presented to you at sign-up and that you confirmed having read it is recorded electronically together with the version number of the text and a timestamp. Consent records are kept in the same way, separately for each item of consent.
This notice may be updated in line with changes in legislation, decisions of the Board or changes in the App's processing activities. Where it is updated, the date of the text is changed; for material changes, Users are additionally informed inside the App.
14. Data controllers' registry (VERBİS) status
Under Article 16 of the Law, natural and legal persons who process personal data must, as a rule, register with the Data Controllers' Registry (VERBİS) before they begin processing. However, the Personal Data Protection Board may grant exemptions from that obligation having regard to objective criteria such as the nature and volume of the personal data processed.
Under the Board's decision no. 2025/1572, data controllers with fewer than 50 employees a year and an annual financial balance sheet total of less than 100 million Turkish lira, whose principal activity is not the processing of special categories of personal data, are exempt from the VERBİS registration obligation. The data controller has not registered with VERBİS, having assessed that it meets these criteria. The VERBİS exemption is not an exemption from the obligations under the Law; the duties to inform, to keep data secure, to respond to data subject applications within 30 days, to notify breaches to the Board within 72 hours and to comply with the rules on transfers abroad all continue to apply.
15. Entry into force and contact
This notice entered into force on . Last updated: 10 September 2026.
You can reach us at kvkk@28istanbul.com for any question or request concerning the processing of your personal data.
Forms a whole together with the Explicit Consent text, the Terms of Use, the Privacy Policy, the Cookie and SDK Policy and the Commercial Electronic Message Consent.
Last updated: 10 September 2026