Privacy Policy & KVKK Notice
Effective: 17 July 2026 · under Turkish Data Protection Law No. 6698 (KVKK)
1. What data do we process?
- Identity & contact: name/display name, e-mail address.
- Account security: an irreversible encrypted digest of your password (the password itself is never stored), and your sign-in method (e-mail or Google).
- Service usage data: your watchlist, trade-ledger entries, portfolio contents, language and interface preferences.
- Technical data: session cookie, IP address, and security/error logs.
2. Purposes and legal bases
- Creating your account and verifying your identity — formation/performance of the contract.
- Providing the service (analysis, watchlist, ledger) — performance of the contract.
- Sending e-mail verification and security notices — legal obligation / legitimate interest.
- Preventing fraud/abuse and securing the system — legitimate interest.
- Responding to lawful requests — legal obligation.
3. Who do we share data with?
We do not sell your data. It is shared only with the infrastructure providers required to operate the service, to the minimum extent necessary:
- Hosting & e-mail: Amazon Web Services (hosting and e-mail delivery infrastructure).
- Network security & acceleration: Cloudflare (CDN, TLS, firewall).
- Authentication (optional): Google LLC, only if you choose to sign in with Google.
Some of these providers are located abroad; your data may therefore be transferred internationally within the scope of KVKK Article 9, limited to what the service requires.
4. How long is data kept?
Your personal data is kept while your account is active and for any retention periods required by law. When you request account deletion, data not subject to a legal retention obligation is deleted or anonymised within a reasonable time.
5. How do we protect your data?
- Passwords are stored using industry-standard, irreversible one-way encryption (hashing) — never in plain text.
- All traffic is encrypted with HTTPS/TLS.
- Each user's data is kept isolated (per-user) from other users.
- Administrative access is kept to a minimum.
6. Your rights under KVKK Article 11
By applying to the data controller you may: learn whether your personal data is processed and request information about it; learn the purpose of processing; know the third parties to whom it is transferred domestically or abroad; request correction of incomplete/inaccurate data; request deletion/destruction where the legal conditions are met; object to a result arising against you from analysis exclusively by automated systems; and claim compensation for damages.
You may submit requests to [email protected]; requests are answered within 30 days at the latest.
7. Changes
This policy may be updated from time to time; the current version is published on this page. Material changes are communicated by reasonable means.
8. Users in the European Union — GDPR
If you are located in the European Union or the European Economic Area, your personal data is covered by Regulation (EU) 2016/679 (GDPR). This section supplements the KVKK sections above; in the event of a conflict, this section prevails for users located in the EU.
8.1 Controller
Finmentis — contact: [email protected]. No data protection officer (DPO) has been appointed at this time; data protection requests should be sent to that address.
8.2 Legal bases for processing (Art. 6)
- Performance of a contract (Art. 6(1)(b)) — creating your account and providing the watchlist, ledger and analyses.
- Legal obligation (Art. 6(1)(c)) — retention of invoicing and accounting records.
- Legitimate interests (Art. 6(1)(f)) — service security, abuse and fraud prevention, fault diagnosis. A balancing test is applied and you may object.
- Consent (Art. 6(1)(a)) — only for non-essential communications; you may withdraw consent at any time.
8.3 Categories of recipients
Your data is not sold. It is shared only with processors necessary to provide the service: cloud hosting and backup providers; the transactional e-mail service; the payment service provider (which acts as merchant of record under its own controllership); market-data providers; and the artificial-intelligence model providers used to generate analyses.
Important: your name, e-mail address, account identifier and portfolio positions are not sent to the analysis engines; only financial-instrument symbols and public market data are processed.
8.4 International transfers (Chapter V)
Some processors are located outside the EU/EEA, primarily in the United States. Such transfers are made on the basis of a European Commission adequacy decision or Standard Contractual Clauses (SCCs). You may request a copy of the safeguards applied by writing to [email protected].
8.5 Retention periods
- Account and service data — for as long as your account is open; deleted within 30 days at the latest after you request deletion.
- Invoicing and accounting records — for the period required by applicable tax law (typically 8–10 years).
- Security logs — 12 months maximum.
8.6 Your rights (Art. 15–22)
- Access (Art. 15) — obtain a copy of the data processed about you.
- Rectification (Art. 16) — correct inaccurate or incomplete data.
- Erasure / right to be forgotten (Art. 17) — have your data deleted.
- Restriction of processing (Art. 18).
- Data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interests.
- Withdrawal of consent — at any time, without affecting prior processing.
Requests should be sent to [email protected] and are answered within one month as a rule. You may also delete your account from within the application.
8.7 Automated decision-making (Art. 22)
The service generates analyses of financial instruments automatically; however, those analyses do not constitute automated individual decisions about you that produce legal effects or similarly significantly affect you. No profiling is carried out and the content is not tailored to the individual.
8.8 Complaint to a supervisory authority
You have the right to lodge a complaint with the data protection authority of your country — for example the competent state data protection commissioner in Germany, the AEPD in Spain, the CNPD in Portugal, the CNIL in France, or the Garante per la protezione dei dati personali in Italy.