MyTavs

Personal Data Processing Notice (KVKK)

prereg-2026-10-02-5 · 02.10.2026

1. Data controller

This notice provides information about data processing under Article 10 of the Republic of Türkiye's Personal Data Protection Law No. 6698 (KVKK). The controller is Andrei Starovoitov, the individual organising free preregistration with MyTavs, located in Antalya, Republic of Türkiye. The city information is not a complete postal address. Personal data questions and requests can be sent to [email protected]. Section 7 explains how to exercise your rights.

This notice covers the website, account, provider profile, customer interest record, Telegram bot and enquiries. MyTavs does not take work orders or payments during preregistration. Acknowledging the notice is not consent to any and all processing.

2. Data and purposes

Data comes from you through the website, contact form, email verification, Telegram messages and emails to [email protected]. When you open the website, infrastructure receives technical request information before you act in a form; when you contact the bot, Telegram sends an identifier and the message content. Collection, recording and storage take place electronically by wholly or partly automated means; the organiser also reviews profiles and enquiries personally.

DataPurpose
Email, verification record, selected role and technical account identifiersCreate an account, send a code and a service confirmation of account creation, enable login and associate actions with the account
Name or team name, service category and description, information about the provider and experience, city, service areas, work format, working languages, contact email or Telegram and supplied public linksReceive and review the profile and assess the supply of services in preparation for a future directory
Customer role and launch interest recordRecord participation in preregistration
Telegram user and chat IDs, typed answers and button actionsRun the conversation and link it to a verified account; automatic Telegram profile names and usernames are not retained as profile fields
Contact form name, email, subject and textReceive and answer the enquiry
Web request network information, including IP address and technical infrastructure logs, cookies, request IDs, registration stage and delivery events, a minimal account confirmation sending recordPrevent abuse and duplicates and check service operation
Document version and language, two acknowledgement actions, channel and time, account association; minimal deletion recordRecord actions and prevent a deleted account returning from an old backup
Sender address, name and contact details in the email, request subject and content, submitted attachments and necessary identification informationReceive the email request, verify the requester proportionately, consider the request and respond
One launch email choice, version launch-2026-10-02-1, language, channel and time of choices/changes, account and verified email association; choice and withdrawal historyRecord the specific voluntary request, enable changes or withdrawal and record the current choice

Internal reports to the organiser use aggregate counts, not profile text or email addresses. Do not send identity documents, banking or health information. If needed for a separate lawful request, a secure collection procedure must be defined separately.

The separate launch email request is processed by the organiser, Andrei Starovoitov, using MyTavs. When an email code is requested, the choice is temporarily included in the encrypted verification record. The active account request and its change history are stored encrypted only after email verification; the technical code record is cleared according to the periods in section 5. Website and bot use involves the infrastructure described in section 4. The feature currently only records the choice; it does not send a launch email, export addresses or synchronise them with Resend marketing lists. The Acknowledgements and messages page explains the voluntary choice in full.

3. Processing purposes and legal grounds

PurposeGround under KVKK
Creating and managing an account, email codes and service confirmation of account creation, receiving a profile or interest record, conversations necessary for requested participationArticle 5(2)(c): data directly necessary to establish and perform the terms of free preregistration
Protecting the website and forms, preventing duplicates and abuse, technical operation and delivery events, remembering the chosen language, answering ordinary enquiriesArticle 5(2)(f): processing necessary for the organiser's legitimate interests in secure operation and responding to enquiries, provided that users' fundamental rights and freedoms are not infringed
Recording acceptance of the terms and provision of the noticeArticle 5(2)(c) for performance of the participation terms; Article 5(2)(ç) for fulfilling the duty to inform
Handling rights requests, fulfilling deletion duties and keeping the minimal deletion ledgerArticle 5(2)(ç): compliance with legal obligations, including KVKK Articles 10 and 13 and requirements to record deletion operations
Keeping information necessary to establish, exercise or protect a specific rightArticle 5(2)(e), limited to the necessary scope and relevant period
Record and fulfil the separate voluntary request for one launch email linked to a verified email addressArticle 5(1): specific, informed and freely given consent for this purpose through a separate optional choice. Once withdrawn, the request is no longer used for sending
Record the choice, changes and withdrawal to establish the request's content and statusArticle 5(2)(e): minimal history necessary to establish, exercise or protect rights, limited to the account period in section 5. The history does not permit sending after withdrawal

Each ground applies to a specific purpose and only when its conditions are met. Free preregistration does not remove necessity and proportionality requirements. Acceptance of the terms, a read acknowledgement and an email code are not blanket processing consent. International transfers are governed separately and are described in section 4.

4. Recipients and international transfers

The organiser accesses data to operate preregistration. Resend receives the address and service email content to deliver codes and confirmation of account creation. Telegram is used for bot conversations and internal profile notifications to the organiser, including profile information and verified email; this also covers profiles submitted on the website. Contact form enquiries are forwarded through Google/Gmail and Telegram. Cloudflare provides website access and protection and processes web request information.

Messages to [email protected] pass through Cloudflare Email Routing and are forwarded to the organiser's Google/Gmail mailbox to receive and handle requests. These services process sender and recipient addresses, message content, attachments if sent, and technical delivery information. Data from requests is not used to create an advertising subscription.

The project's main infrastructure is on a NAS/VM in Turkey. Encrypted backups are created, including copies on the organiser's laptop. The countries of all copies and remote access locations have not been fully established.

These external services may process data outside Turkey. Using them for the website, emails and notifications creates regular data flows. MyTavs has not yet confirmed an applicable KVKK Article 9 transfer mechanism, a complete country list or recipients' contractual roles for these flows. This remains an unresolved issue concerning the lawfulness of international transfers. Accepting the terms, reading the notice, encryption and having the main database in Turkey do not replace a transfer mechanism. The explicit consent exception for incidental transfers under Article 9(6) is not a general basis for regular flows.

5. Retention and deletion

The active database is cleaned periodically, normally hourly. These periods are thresholds for the next cleanup, not promises of deletion at an exact second.

CategoryImplemented period
Account, associated role data, customer interest and document acknowledgements180 days from account creation; logging in again does not restart the period
Provider profile and separate legacy waiting list records180 days from the respective record's creation; account deletion may remove a profile earlier
Contact form enquiry90 days from creation
Registration stage events90 days
Temporary registration link1 day
Email code and login sessionCode valid for 10 minutes; session up to 7 days; expired technical records are cleaned up
Telegram conversation working stateAfter 30 days without activity; technical incoming/outgoing bot and admin interface records are cleaned up 30 days after creation
Minimal deletion ledger1098 days from deletion, then the next cleanup; contains a technical link to the deleted record, not the retained profile
Launch email choice and the history of choices, changes and withdrawalRemoved from the active database with the account: at the next cleanup after 180 days from account creation, or earlier if the account is deleted. Changing the choice does not extend this period; withdrawal stops the request being used for sending
Account confirmation queue and minimal outcome recordBefore email verification, a waiting record is kept within the account period. After email verification, the queue period is 24 hours. The address and content are encrypted and removed from the active queue after sending completes, attempts stop or cleanup after expiry. A minimal record containing the technical account identifier, times, status and attempt count remains to prevent duplicate sending and is removed with the account; the account period is not extended

Account deletion removes associated records from the active database, including document acknowledgements, and ends access. A separate contact form enquiry is not linked to the account, has its own retention period and is not automatically removed with the account. Restoring an old backup requires applying the current deletion ledger.

Database cleanup frequency does not determine backup retention. Different backup sets use rotation by counts of 7 and 30 copies; these do not mean 7 and 30 days. A single calendar limit for all backup, release and recovery copies has not been established. Account deletion does not automatically remove delivered emails, Telegram cards or external provider copies. Their exact periods and deletion procedures have not been confirmed. Emails to [email protected] are held separately from the active database; the table's automatic periods do not apply to them, and a common retention period has not yet been established.

When all applicable processing grounds cease, data must be erased, destroyed or anonymised. This duty also covers backups and data transferred to recipients; the account deletion function's limitations do not remove it. Where data has been transferred to third parties, the controller must notify them and ensure the necessary actions under the applicable regulation. Deletion requests must be concluded within 30 days; retaining specific information under a continuing legal ground requires an explanation to the requester. Minimal records of deletion operations are retained for at least three years, rather than retaining the profile itself.

6. Cookies and browser storage

ItemPurpose and period
mytavs_account cookieAccount login, up to 7 days; HttpOnly, SameSite=Lax, Secure on HTTPS. The session is revoked on logout or deletion
tavs_session cookieForm protection and linking actions to the browser; server validity up to 24 hours from issuance; HttpOnly, SameSite=Lax, Secure on HTTPS
localStorage mytavs_languageru, tr or en preference; no application expiry, kept until changed or cleared by the browser
sessionStorage tavs_provider_request, tavs_customer_request, tavs_feedback_requestRandom identifiers preventing duplicate submissions; renewed after the relevant action, generally kept for the tab session

The application does not write profile contents into these browser stores. The table describes application items. Cloudflare separately processes technical information and infrastructure logs for website access and protection; this table is not a complete inventory of the external provider's processing. The project's current code contains no advertising trackers. Blocking or clearing necessary cookies may interrupt login and forms.

7. Rights and request procedure

Under KVKK Article 11, you may:

You can withdraw your separate consent to one launch email at any time in your account or through [email protected]. Withdrawal ends use of the request for that email; it does not cancel necessary processing under another applicable ground. This interface does not request blanket international transfer consent, and withdrawal does not resolve the issue described in section 4.

Send requests to [email protected], including after account deletion. For an ordinary email request under the Communiqué, use an address previously supplied to MyTavs and recorded in its system. A formal request must be in Turkish and include your name, surname, request subject, notification address and the identification details required by Article 5(2) of the Communiqué; a signature is required for a written application. Include available contact details for the response.

If you cannot access your previous email or the record has been deleted, write to the same address to arrange a legally recognised submission method and proportionate identity verification. This does not exclude written requests or other methods provided by law, including KEP, a secure electronic signature or a mobile signature. The contact form also receives questions and requests; it is not the only way to exercise rights. Only necessary information is used to verify a requester; do not send a passport copy, banking or health documents through the ordinary contact form or Telegram. If additional verification is needed, a secure way to provide information will be arranged separately.

The controller must conclude a request as soon as possible and within 30 days of receipt at the latest. The final response is provided in writing or electronically; any refusal must state its reasons. Requests are free of charge except for additional costs expressly permitted by the tariff set by KVKK. If a response is late, insufficient or refuses the request, you may complain to the Board within 30 days of learning of the response and, in any event, within 60 days of the request to the controller. Rights to seek judicial remedies remain available.