Privacy Notice (KVKK)
Version 1.0 · Published 8 October 2026
Draft — requires review by a lawyer. This text is not legal advice; have it reviewed by a lawyer before publishing.
This privacy notice is provided under Article 10 of the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and the Communiqué on the Procedures and Principles for Fulfilling the Obligation to Inform, in order to inform the users (clients, chefs and visitors) of the private-chef marketplace platform operated at https://sef.verifull.cloud (the “Platform”). In case of any discrepancy, the Turkish version prevails.
1. Data controller
Your personal data is processed by the following company as data controller:
- Company title: [COMPANY_TITLE]
- Address: [COMPANY_ADDRESS]
- MERSIS No: [COMPANY_MERSIS]
- Tax office / No: [COMPANY_TAX_OFFICE] / [COMPANY_TAX_NO]
- Email: [COMPANY_EMAIL]
- Phone: [COMPANY_PHONE]
- Registered e-mail (KEP): [COMPANY_KEP]
The Platform is an intermediary service provider that connects clients with independent chefs. Chefs are not employees or agents of the Platform; chefs may separately act as data controllers for data they obtain in their direct relationship with clients after an unlock.
2. Categories of personal data processed
| Category | Examples | Data subject |
|---|---|---|
| Identity | First and last name; for chefs, an image of the national ID document | Client, chef |
| Contact | Email address, phone number, Instagram username | Client, chef |
| Customer transaction | Inquiry details (event date, guest count, location, budget range, note), unlock and credit records, reviews | Client, chef |
| Financial | Payment transaction reference, amount, invoice details (e-Archive); card details are not stored on Platform servers | Client, chef |
| Professional documents | Hygiene certificate, tax certificate, other uploaded documents | Chef |
| Visual | Profile photo, portfolio and menu images | Chef |
| Transaction security | IP address, session data, login records, device/browser data, error logs | All users |
| Communication content | In-platform messages (contact details are automatically masked before unlock) | Client, chef |
| Legal transaction and consent | Text version, date and IP address of approvals and consents given | All users |
| Marketing | Commercial electronic message preference | Users who opted in |
3. Purposes of processing
Your personal data is processed for the following purposes:
- Creating your account, authentication and account management (including Google sign-in),
- Creating inquiries, forwarding them to chefs, managing the 48-hour response window and performing the unlock service,
- Processing payments and pre-authorizations, maintaining credit balances and issuing refunds,
- Issuing e-Archive invoices and complying with statutory retention obligations,
- Verifying chef documents and having profiles approved by an administrator,
- Providing in-platform messaging and preventing the sharing of contact details before unlock (masking),
- Preventing fraud, fake inquiries and abuse, and ensuring information security,
- Detecting errors, measuring and improving service quality,
- Translating content,
- Handling complaints, refunds and disputes,
- Responding to information requests from competent authorities,
- Sending commercial electronic messages where you have given explicit consent.
4. Legal grounds
Your personal data is processed on the following legal grounds under Articles 5 and 6 KVKK:
- Establishment or performance of a contract (Art. 5/2-c): Membership, inquiries, unlocks, credit packs and Chef Pro membership.
- Compliance with a legal obligation (Art. 5/2-ç): Issuing and retaining invoices under tax law, traffic logs under Law No. 5651, disclosures to competent authorities.
- Establishment, exercise or protection of a right (Art. 5/2-e): Disputes, refunds and complaints; retaining consent records as evidence.
- Legitimate interest (Art. 5/2-f): Information security, bot protection, error tracking, preventing abuse and off-platform circumvention, service improvement.
- Explicit consent (Art. 5/1): Paid sharing of chef contact details, commercial electronic messages, analytics cookies and cross-border data transfer.
- Special categories of data (Art. 6): An ID document may contain special-category data such as religion or blood type; processing such data is not intended and chefs are asked to cover these fields before uploading. Where necessary, explicit consent is obtained under Art. 6/3. [lawyer to assess]
5. Transfer of personal data
5.1. Domestic transfers
- To chefs and clients: If the chef accepts an inquiry and the client pays the fee or uses a credit, the chef’s name, phone, email and Instagram details are shared with that client based on the chef’s explicit consent. An inquiry summary (excluding the client’s contact details) is forwarded to the chef.
- To the payment institution: Iyzico Ödeme Hizmetleri A.Ş., for payment and pre-authorization transactions.
- To the e-Archive integrator: For issuing invoices.
- To competent public authorities: Where requested under a legal obligation.
- To legal and financial advisors: For the protection of a right.
5.2. Cross-border transfers (Art. 9 KVKK)
The Platform’s technical infrastructure uses service providers established abroad: Cloudflare (hosting, storage, Turnstile bot protection), Resend (email delivery), Sentry (error tracking), PostHog (EU region, analytics), Google (Google sign-in) and optionally Anthropic (translation and contact-leak detection). These transfers are carried out by signing the standard contractual clauses published by the Personal Data Protection Board and notifying the Board, or, where this is not possible, based on your explicit consent.
6. Method of collection
Your personal data is collected electronically, by fully or partly automated means, through registration, profile, inquiry and contact forms on the Platform, Google sign-in, document upload fields, in-platform messaging, the payment page (Iyzico), cookies and similar technologies, and server logs.
7. Retention periods
Personal data is retained for as long as required by the processing purpose and for the maximum periods set out in applicable law. Invoices and accounting records are retained for 10 years under the Tax Procedure Law and the Turkish Commercial Code, traffic logs for 2 years, and consent records for the limitation period after the relevant contractual relationship ends. At the end of the period data is deleted, destroyed or anonymized. [lawyer to assess]
8. Your rights under Article 11 KVKK
As a data subject you have the right to:
- Learn whether your personal data is processed,
- Request information if it has been processed,
- Learn the purpose of processing and whether it is used in line with that purpose,
- Know the third parties to whom it is transferred domestically or abroad,
- Request rectification if it is incomplete or inaccurate,
- Request erasure or destruction under Article 7 KVKK,
- Request that rectification, erasure or destruction be notified to third parties to whom the data was transferred,
- Object to a result against you arising from analysis exclusively by automated systems,
- Claim compensation for damage arising from unlawful processing.
9. How to apply
Via your account: After signing in, you can download a copy of your personal data from the “Download my data” screen on the /hesap page, and request account deletion from the “Delete my account” screen. Data subject to statutory retention (e.g. invoices) continues to be retained for that period.
Written application: Under the Communiqué on the Procedures and Principles of Application to the Data Controller, you may submit your request:
- In writing with a wet signature to [COMPANY_ADDRESS],
- Via registered e-mail (KEP) to [COMPANY_KEP],
- From the email address registered on the Platform to [COMPANY_EMAIL].
Your application must include your name, surname, Turkish ID number (nationality and passport number for foreigners), address for notifications, email and phone if any, and the subject of your request. Applications are concluded free of charge within 30 days at the latest; if the process requires additional cost, the fee set by the Board may be charged.
If your application is rejected, the response is insufficient, or no response is given in time, you may file a complaint with the Personal Data Protection Board.