Personal Data Protection (KVKK)
Minimal data processing, full rights and security in on-premise deployment
Last Update: November 30, 2025
Active / On-Premise Architecture
Table of Contents
IMPORTANT NOTE
Even in on-premise deployment, there is KVKK obligation. However, since your data is not stored at Cayra, the risk is minimal.
Who We Are
Company: CAYRA ARTIFICIAL INTELLIGENCE TECHNOLOGIES INC.
Trade Registry No: Trade Registry No: 536999
Tax No: Tax No: 2030912417
Address: UNIVERSITIES MAH. 1596 ST. TEKNOKENT INCUBATION CENTER BUILDING NO: 6C ΓANKAYA / ANKARA
Email: privacy@cayra.io
Our Role: Data Processor under KVKK
Your Role: Personal Data Controller
KVKK Scope - Who is Included?
KVKK Article 2: "This Law applies to persons and organizations established in Turkey or processing personal data relating to persons in Turkey."
Cayra's Status:
- β Ankara-based β Established in Turkey
- β Has Turkish customers β Processing Turkish persons' data
- β Collects email, username β Processing personal data
Conclusion: KVKK MANDATORY
Processed Data
The following metadata is processed (Customer data NEVER):
Account Information
- β’ Email
- β’ Username
- β’ Password (hashed)
Purpose: Authentication
Retention Period: Until account deletion
Legal Basis: KVKK Art. 8(b) - Contract
Technical Logs
- β’ IP address
- β’ Browser
- β’ Session duration
Purpose: Security, debugging
Retention Period: 365 days (Legal requirement)
Legal Basis: KVKK Art. 8(d) - Legitimate Interest
Queries (Optional)
"What are last month's sales?" β Being anonymized
Purpose: AI model training
Retention Period: 90 days
Legal Basis: KVKK Art. 8(a) - Explicit Consent
Note: You may not give consent
Early Access / Waitlist Form
- β’ First name, last name
- β’ Email address
- β’ Phone number (optional)
- β’ Company name (optional)
- β’ Sector (optional)
- β’ Query/text typed in the form at the time of access (optional)
Purpose: Evaluating early access applications and creating access accounts
Retention Period: 2 years from the conclusion of the application
Legal Basis: KVKK Art. 8(b) - Contract + KVKK Art. 8(d) - Legitimate Interest
Data is transferred abroad via third-party service providers for identity management and email delivery, pursuant to your explicit consent under KVKK Art. 9.
| Data | Purpose | Duration | Legal Basis |
|---|---|---|---|
| Email, username | Authentication | Until account deletion | KVKK Art. 8(b) |
| IP Address | Security, debugging | 365 days | KVKK Art. 8(d) |
| Query (anonymized) | AI training | 90 days | KVKK Art. 8(a) + Consent |
| Password (hashed) | Login | Until account deletion | KVKK Art. 8(b) |
Legal Bases
Cayra processes your metadata under the following legal bases:
KVKK Art. 8(b): Contract Performance
- β’ Login and account management
KVKK Art. 8(d): Legitimate Interest
- β’ System security
- β’ Debugging
- β’ Performance monitoring
KVKK Art. 8(a): Explicit Consent [Optional]
- β’ AI model training (anonymous)
Your Rights (KVKK Art. 11-14)
Under KVKK, you have the following rights:
1. Right of Access
What information is stored at Cayra? Learn.
Request: Request: privacy@cayra.io
Response: Response: Within 30 days
2. Right to Rectification
Correct if there is incorrect information.
Request: Request: privacy@cayra.io
3. Right to Deletion (Right to be Forgotten)
You can delete your account; all data is deleted.
Request: Request: privacy@cayra.io
Response: Response: Within 30 days
If you want to cancel your account: Send email to privacy@cayra.io. Within 30 days: Your account is deleted, All metadata is deleted, Deletion proof is sent to you
4. Data Portability
Export your data (JSON, CSV).
Request: Request: privacy@cayra.io
Response: Response: Within 30 days
5. Right to Object
Object to data processing.
Request: Request: privacy@cayra.io
6. Right to Processing Restriction (KVKK Art. 14)
You can request restriction of certain data processing.
Request: Request: privacy@cayra.io
Response: Response: Within 30 days
Examples:
- β’ Stop data processing for AI training
- β’ Disable analytics cookies
- β’ Limit data processing for a specific purpose
Legal Basis: KVKK Art. 14 - Right to Processing Restriction
All FREE
Response Time: 30 days (KVKK Art. 13)
Contact: privacy@cayra.io
Data Security Measures (KVKK Art. 12)
KVKK Art. 12: "Data processor must take technical and administrative measures."
- β TLS 1.3 encryption (during transmission)
- β bcrypt/Argon2 hashing (passwords)
- β Role-based access control
- β Regular penetration testing
- β Log integrity (SHA-256 + timestamp)
On-Premise and Cloud Comparison
ON-PREMISE:
- β’ Data: Never stored at Cayra
- β’ KVKK: Minimal (account information only)
- β’ Risk: Very low
Important: Your data is not stored at Cayra. Cayra only processes metadata (login information, logs). Conclusion: KVKK risk is very low.
CLOUD (TEST):
- β’ Metadata: Stored at Cayra for 30 days
- β’ KVKK: Applicable (metadata)
- β’ Risk: Low (data never stored)
Warning: Metadata is in Cayra cloud for 30 days. However: β Data is never stored, β GDPR compliant (with SCC), β Regular deletion (automatic)
KVKK Obligations in On-Premise Deployment
Mandatory Articles
β MANDATORY: Article 4 - Data Processor Definition
Cayra defines itself as "data processor". Email, address, trade registry number are added.
β MANDATORY: Article 8 - Legal Basis
1. Art. 8(b): Contract Performance (Login, account management), 2. Art. 8(d): Legitimate Interest (Security, fraud detection), 3. Art. 8(a): Explicit Consent (AI training - optional)
β MANDATORY: Article 11 - Right to Data Deletion
If customer requests: Delete account + all metadata. Duration: Within 30 days (Art. 13). Document: Send deletion proof to customer
β MANDATORY: Article 12 - Data Security
TLS 1.3 encryption, bcrypt/Argon2 hashing, role-based access control, log keeping (integrity)
β MANDATORY: Article 13 - Response to Right Request
Deletion requests: 30 days, Access requests: 30 days, Portability: 30 days. Document: Send written response
Conditional Obligations
β οΈ MANDATORY IF APPLICABLE: Article 16 - Breach Notification
KVKK Art. 16: "Personal data breach may be notified to the individual."
On-Premise:
Data never stored β Breach impossible β Notification not required
Since there is no actual data at Cayra, data breach is not possible. Only metadata (account information, logs) is processed.
Cloud:
Metadata stored β Breach possible β Notification required
Breach Notification Procedure:
- β’ Breach detection: Within 24 hours
- β’ Notification to KVKK Board: Within 72 hours
- β’ Notification to affected individuals: As soon as possible
- β’ Nature of breach (which data was leaked)
- β’ Possible consequences (who was affected)
- β’ Measures taken (what was done)
- β’ Individual-specific damage risk (if any)
Email, phone, platform notification
If you use Cayra cloud deployment and data breach occurs: You are notified within 24 hours, Reported to relevant authorities
β οΈ MANDATORY IF APPLICABLE: Article 19 - International Transfer
International Data Transfer: Your query and schema: OpenAI (USA) / Anthropic (USA), Data: NEVER leaves, Protection: GDPR Standard Contractual Clauses (SCC)
On-Premise: Data never leaves β Not required
Cloud: To OpenAI/Anthropic (USA) β Required
Which Data Under KVKK Scope?
| Data | Subject to KVKK | Why |
|---|---|---|
| β YES (Art. 3-f) | Personally identifiable | |
| Username | β YES (Art. 3-f) | Personally identifiable |
| Password (hashed) | β YES (Art. 3-f) | Authentication |
| IP Address | β YES (Art. 3-f) | Personally identifiable |
| Technical Logs | β YES (Art. 3-f) | Session duration, time |
| Query (e.g.: "sales") | β οΈ DEBATABLE | If anonymous, outside KVKK |
| Schema (table names) | β NO | Not personal data |
| Customer Data | β NO | Stays with customer |
Conclusion: Cayra processes minimum metadata