Otomedik
Legal

KVKK Information Notice

Information notice under Türkiye’s Personal Data Protection Law No. 6698 (“KVKK”) on how Otomedik processes personal data when you use the platform.

Version 1.0 · Effective date will be set at production launch.

Sections that contain legal interpretation must be reviewed by a Turkish lawyer before production. Marked headings fall in that scope.

1. Data controllerLawyer review

This notice covers the online vehicle marketplace operated under the Otomedik brand.

The data controller’s legal trade name, registered address, and tax identification number have not yet been supplied in production configuration:

  • Legal name: Şahıs Şirketi
  • Address: Denizli / Pamukkale
  • Tax ID: 12345678901
  • KVKK requests: [email protected]

These fields must be completed with official company information before production launch. This notice is a draft based on the current software architecture; it is not a final legal instrument.

2. Personal data categories

Otomedik only processes data the application actually collects or stores. The categories below come from the codebase:

Identity. Full name (individual accounts); company name (dealer, rental company, repair service).

Contact. Email (stored in Firebase Authentication, not in the MongoDB profile); phone; WhatsApp on business accounts; optional social / website URLs.

Account. Account type (individual, dealer, rental company, repair service); Firebase user ID; profile-completion flag; verified badge (boolean); rating and review count.

Business. Logo and cover image; Turkish/English descriptions; founding year; staff-count range; working hours; auto-reply preference; rental minimum age / licence years; repair specialties and brand authorizations.

Tax identifiers. Optional tax number and tax office on business accounts. These fields are not returned on public profile APIs; only the signed-in owner sees them on their own profile. Otomedik does not currently upload tax certificates or similar verification documents.

Listings. Title, description, price, city/district, photos, vehicle specs, damage/paint report, rental availability and pricing rules.

Bookings. Rental listing, renter account id, start/end dates, status, computed total price. Booking records do not store a separate guest name, email, or phone.

Messaging. Message body and timestamp between two participants. Threads are visible only to those participants.

Location. City and district; on business accounts, pinned map latitude/longitude and full address (selected via Google Maps / Places). Listings do not store a street address.

Device / analytics. If you grant consent in the browser, Firebase Analytics may collect usage statistics. The API does not keep access logs of IP or user-agent. IP and user-agent may be stored only on legal-acceptance records as evidence of acknowledgement/acceptance.

Authentication. Email/password or Google sign-in; passwords are not stored on Otomedik servers (Firebase Authentication).

Uploaded images. Avatar, logo, cover, staff, listing, and repair photos in Firebase Storage. Storage rules allow public read of these images, which is required for listings and the business directory.

Verification. “Verified” is a badge an administrator can set. There is no document-based verification workflow yet.

Staff. Name, role, optional photo and phone entered by the business, published on directory pages.

Reviews. Rating, comment, and the author’s profile name are public.

Otomedik does not collect payment-card data, marketing lists, or a dedicated vehicle licence-plate / registration field. The current contact form does not submit data to a server.

3. Processing purposes

Personal data is processed for the following purposes — we do not claim purposes the application does not support:

  • Creating and managing user accounts
  • Publishing listings and providing marketplace functionality
  • Displaying dealer, rental-company, and repair-service directory pages
  • Enabling messaging between parties
  • Forwarding and tracking rental booking requests
  • Displaying ratings and reviews
  • Storing a business tax identifier for the account owner (not public)
  • Showing images on listings and profiles
  • Security and abuse prevention (the current architecture has no separate IP access-log system)
  • Admin operations (disable/delete accounts, content management)
  • Complying with legal obligations
  • Service improvement via Firebase Analytics only when explicit consent is given

Otomedik does not currently send marketing email, commercial electronic messages, or process payments.

5. How data is collected

Data is collected through:

  • Registration and profile forms (email/password or Google sign-in)
  • Listing create/edit
  • Messaging and booking requests
  • The review form
  • Map / address autocomplete (Google)
  • Admin panel actions
  • Firebase Analytics if analytics consent is granted in the browser
  • A device notification token (Firebase Cloud Messaging) if push notifications are enabled
  • Legal-document acceptance at registration (version, timestamp; IP and user-agent where justified)

The Otomedik API does not log IP addresses on every request.

6. Transfers and third partiesLawyer review

Personal data may be disclosed to the following recipients as needed to run the service. We do not claim transfers to services the code does not use.

  • Google Firebase Authentication, Cloud Storage, and Analytics. Authentication, image hosting, and (consent-based) analytics. Data may be processed on Google infrastructure, which can mean a cross-border transfer.
  • Google Maps and Places. Address search and map pinning may send address/location data to Google.
  • MongoDB. Primary database for accounts, listings, messages, bookings, and acceptance records. Hosting region must be confirmed before production.
  • API hosting. The API is configured with a Railway production reference in code; the exact region must be confirmed.
  • OpenAI. Admin blog-draft generation only; ordinary user account data is not sent this way.

Messaging runs over Socket.IO on the same API process, not a separate vendor.

Whether these cross-border transfers comply with KVKK Art. 9 and Board decisions requires lawyer review. Standard contractual clauses or consent requirements are not settled in this draft.

7. RetentionLawyer review

Concrete retention periods have not yet been set by an accountant or lawyer.

Draft rule: account data while the account exists; listings possibly longer if a legal duty remains after removal; messages and bookings for the service relationship and any dispute window; legal-acceptance records with the account or for a legally required minimum.

Account deletion is not a self-service API today. Requests go to [email protected]; an administrator can delete the Firebase Authentication user and MongoDB profile.

8. Data subject rightsLawyer review

Under KVKK Art. 11 you may apply to the controller to:

  • Learn whether your personal data is processed
  • Request information if it is
  • Learn the purpose of processing and whether it is used in line with that purpose
  • Know the third parties to whom it is transferred domestically or abroad
  • Request correction of incomplete or inaccurate data
  • Request deletion or destruction under the conditions in KVKK Art. 7
  • Request that correction/deletion be notified to third parties
  • Object to a result against you arising exclusively from automated systems
  • Request compensation if you suffer damage from unlawful processing

Apply at: [email protected]

Procedure and time limits (KVKK Art. 13 and related communiqués) should be confirmed with a lawyer. This notice does not limit your right to complain to the Board.

9. Contact and updates

KVKK requests: [email protected]

This notice is version 1.0. The effective date will be set at production launch. Material changes increment the version; the version accepted at account creation is stored on the server.

The English text is a courtesy translation. In case of conflict, the Turkish text prevails.