KVKK Clarification Text
1. Data Controller
Within the scope of the Turkish Personal Data Protection Law No. 6698, your personal data is processed by [Company Legal Name] as the data controller.
Data controller information:
Company: [Company Legal Name]
Address: [Address]
Email: [Email]
Phone: [Phone]
This clarification text has been prepared to inform individuals who visit, use, create an account on, submit a support request through, respond to a support request on, or otherwise interact with the Tixenta platform.
2. Personal Data Processed
The following personal data may be processed within the scope of your use of Tixenta:
| Data Category | Examples |
| Identity information | Name, surname, username |
| Contact information | Email address, phone number |
| Customer/company information | Company name, department, role, authorization information |
| Account and transaction information | User role, login information, account status, notification preferences |
| Request and support information | Ticket title, ticket content, messages, status information, priority, category, department, attachment information |
| Transaction security information | IP address, session information, device/browser information, security logs, CSRF and session cookies |
| Technical records | System logs, error records, transaction time, access records |
Users are expected not to enter special categories of personal data or unnecessary personal data belonging to third parties into support request or message fields.
3. Purposes of Processing Personal Data
Your personal data may be processed for the following purposes:
- Creating and managing user accounts,
- Carrying out authentication and authorization processes,
- Creating, assigning, responding to, and resolving support requests,
- Managing customer, staff, department, and role-based workflows,
- Sending notifications,
- Ensuring platform security,
- Preventing unauthorized access, misuse, and security breaches,
- Monitoring system performance, error records, and transaction logs,
- Improving service quality,
- Fulfilling legal obligations,
- Exercising or protecting rights in case of potential disputes.
4. Legal Grounds for Processing Personal Data
Your personal data may be processed based on the following legal grounds under the Turkish Personal Data Protection Law:
- Processing is necessary for the establishment or performance of a contract,
- Processing is necessary for the data controller to fulfill its legal obligations,
- Processing is necessary for the establishment, exercise, or protection of a right,
- Processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject,
- Processing is clearly provided for by law.
If a separate personal data processing activity requiring explicit consent arises, your explicit consent will be requested separately for that activity.
5. Method of Collecting Personal Data
Your personal data may be collected electronically through:
- The Tixenta web application,
- Login and registration forms,
- Support request/ticket forms,
- User panel,
- Email notifications,
- Integrations,
- Cookies,
- System and security logs.
6. Transfer of Personal Data
Your personal data may be shared with the following parties, limited to the purposes of processing:
- Authorized public institutions and organizations,
- Legally authorized persons and authorities,
- Hosting, infrastructure, security, email, notification, maintenance, and technical support service providers,
- Business partners and suppliers required for the provision of the Tixenta service,
- Integration providers used for service delivery.
Your personal data is shared only to the extent necessary for providing the service.
If the use of an infrastructure, integration, or service provider requires the transfer of personal data abroad, such transfer is carried out in accordance with applicable legislation.
7. Retention of Personal Data
Your personal data is retained for as long as required by the purposes of processing and for the legal retention periods specified under applicable legislation.
When the retention period expires or the purpose of processing no longer exists, your personal data is deleted, destroyed, or anonymized.
Ticket, transaction, security, and log records may be retained for the period necessary for service continuity, security, audit, and resolution of potential disputes.
8. Rights of the Data Subject
Under Article 11 of the Turkish Personal Data Protection Law, you have the right to:
- Learn whether your personal data is being processed,
- Request information if your personal data has been processed,
- Learn the purpose of processing and whether your data is used in accordance with that purpose,
- Know the third parties to whom your personal data has been transferred domestically or abroad,
- Request correction if your personal data has been processed incompletely or incorrectly,
- Request deletion or destruction of your personal data within the framework of the conditions set out under applicable legislation,
- Request notification of correction, deletion, or destruction to third parties to whom your personal data has been transferred,
- Object to any result against you arising from the analysis of your processed data exclusively through automated systems,
- Request compensation if you suffer damage due to unlawful processing of your personal data.
9. Application Method
You may submit your requests under the Turkish Personal Data Protection Law through the following communication channels:
Email: [Email]
Address: [Address]
Applications will be concluded as soon as possible and within the periods specified under applicable legislation, depending on the nature of the request.
Last updated: 3 Jul 2026
