KVKK Privacy Notice

This notice explains how the personal data of people who open an account on and use the Dualyx Appointment platform (the "Platform") is processed, in accordance with Article 10 of Personal Data Protection Law No. 6698 ("KVKK") and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform.

Version: v1 · Last updated: 4 September 2026

1. Identity of the data controller

2. Scope of this notice and the separation of roles

The Platform is a multi-tenant business service on which businesses manage their own appointment and customer operations. There are therefore two separate processing relationships:

3. Personal data processed

Identity and contact data: Full name, email address, phone number, date of birth where provided, profile photo, language and time zone preference.

Business information: Business name, address, phone number, owner name, tax number and tax office, logo. For a sole trader this information may itself constitute personal data.

Account security data: The irreversibly hashed form of the password, email verification and password reset records, one-time sign-in codes, session records, sign-in attempts and registration attempts, and the IP address associated with those records.

Usage and transaction security data: Audit records of operations performed in the Panel (who, when, on which record), in-business change records, application version and error logs.

Support data: Support requests and feedback submitted, their attachments and the correspondence on them.

Contract and subscription data: Trial and package start/end dates, assigned feature entitlements, storage usage, and the version and time of acceptance of the terms of use.

The Platform takes no online payments and processes no card data.

4. Purposes of processing

5. Legal grounds for processing

Where processing relies on explicit consent, that is stated separately and the consent can be withdrawn at any time.

6. Method of collection

Data is collected through registration and sign-in forms, fields filled in within the Panel, the support screen, email correspondence, and records kept automatically by the Platform and its infrastructure components, by partly automated or automated means.

7. Recipients of personal data and purposes of transfer

Under KVKK Art. 8, your data is transferred only to the extent necessary to operate the service, for the following purposes:

Your personal data is not sold or transferred to third parties for advertising or marketing purposes.

8. Transfers abroad

Some of the service providers used have servers outside Türkiye. The Platform's servers are hosted on Hetzner infrastructure, in the [SERVER REGION] region; bot protection runs on Cloudflare and WhatsApp messages run over Meta infrastructure.

These transfers are carried out in accordance with the conditions set out in KVKK Art. 9, relying on an adequacy decision, one of the appropriate safeguards (including standard contractual clauses) or one of the exceptions listed in the Law. Transfers based on standard contractual clauses are notified to the Personal Data Protection Authority.

9. Retention periods

When the service relationship ends, data is deleted or anonymised within the periods described in the Account and Data Deletion document, subject to retention obligations arising from legislation.

10. Data security

Data is encrypted in transit. Passwords are stored irreversibly. Provider credentials are held encrypted and masked in the interface. Each business's data is separated by a tenant identifier (businessId) and authorisation checks are enforced server-side. Access rights are limited to what a role requires, and Panel operations are written to audit records.

11. Your rights as a data subject

Under KVKK Art. 11 you have the right to: learn whether your personal data is being processed; request information if it has been processed; learn the purpose of processing and whether the data is used in line with that purpose; know the third parties to whom the data is transferred in Türkiye or abroad; request correction of incomplete or inaccurate data; request erasure or destruction within the conditions set out in the Law; request that correction and erasure be notified to third parties to whom the data was transferred; object to an adverse outcome arising from analysis carried out solely by automated systems; and claim compensation if you suffer loss due to unlawful processing.

12. How to submit a request

Under the Communiqué on the Procedures and Principles of Application to the Data Controller, you may submit your requests:

Your application must include your full name; your signature if it is in writing; your national identification number (passport number for foreign nationals); your address for notification; your email address and phone number if any; and the subject of your request. Requests are concluded free of charge as soon as possible and in any event within 30 days; where the process entails an additional cost, the fee in the tariff set by the Board may be charged.

If your application is refused, you find the response insufficient, or no response is given in time, you have the right to lodge a complaint with the Personal Data Protection Board.

13. Changes

This notice may be updated. The current version is always published at this address with its version number and last-updated date. Significant changes are communicated through the Panel.