Personal Data Processing Notice (KVKK)
prereg-2026-10-02-5 · 02.10.2026
1. Data controller
This notice provides information about data processing under Article 10 of the Republic of Türkiye's Personal Data Protection Law No. 6698 (KVKK). The controller is Andrei Starovoitov, the individual organising free preregistration with MyTavs, located in Antalya, Republic of Türkiye. The city information is not a complete postal address. Personal data questions and requests can be sent to [email protected]. Section 7 explains how to exercise your rights.
This notice covers the website, account, provider profile, customer interest record, Telegram bot and enquiries. MyTavs does not take work orders or payments during preregistration. Acknowledging the notice is not consent to any and all processing.
2. Data and purposes
Data comes from you through the website, contact form, email verification, Telegram messages and emails to [email protected]. When you open the website, infrastructure receives technical request information before you act in a form; when you contact the bot, Telegram sends an identifier and the message content. Collection, recording and storage take place electronically by wholly or partly automated means; the organiser also reviews profiles and enquiries personally.
| Data | Purpose |
|---|---|
| Email, verification record, selected role and technical account identifiers | Create an account, send a code and a service confirmation of account creation, enable login and associate actions with the account |
| Name or team name, service category and description, information about the provider and experience, city, service areas, work format, working languages, contact email or Telegram and supplied public links | Receive and review the profile and assess the supply of services in preparation for a future directory |
| Customer role and launch interest record | Record participation in preregistration |
| Telegram user and chat IDs, typed answers and button actions | Run the conversation and link it to a verified account; automatic Telegram profile names and usernames are not retained as profile fields |
| Contact form name, email, subject and text | Receive and answer the enquiry |
| Web request network information, including IP address and technical infrastructure logs, cookies, request IDs, registration stage and delivery events, a minimal account confirmation sending record | Prevent abuse and duplicates and check service operation |
| Document version and language, two acknowledgement actions, channel and time, account association; minimal deletion record | Record actions and prevent a deleted account returning from an old backup |
| Sender address, name and contact details in the email, request subject and content, submitted attachments and necessary identification information | Receive the email request, verify the requester proportionately, consider the request and respond |
| One launch email choice, version launch-2026-10-02-1, language, channel and time of choices/changes, account and verified email association; choice and withdrawal history | Record the specific voluntary request, enable changes or withdrawal and record the current choice |
Internal reports to the organiser use aggregate counts, not profile text or email addresses. Do not send identity documents, banking or health information. If needed for a separate lawful request, a secure collection procedure must be defined separately.
The separate launch email request is processed by the organiser, Andrei Starovoitov, using MyTavs. When an email code is requested, the choice is temporarily included in the encrypted verification record. The active account request and its change history are stored encrypted only after email verification; the technical code record is cleared according to the periods in section 5. Website and bot use involves the infrastructure described in section 4. The feature currently only records the choice; it does not send a launch email, export addresses or synchronise them with Resend marketing lists. The Acknowledgements and messages page explains the voluntary choice in full.
3. Processing purposes and legal grounds
| Purpose | Ground under KVKK |
|---|---|
| Creating and managing an account, email codes and service confirmation of account creation, receiving a profile or interest record, conversations necessary for requested participation | Article 5(2)(c): data directly necessary to establish and perform the terms of free preregistration |
| Protecting the website and forms, preventing duplicates and abuse, technical operation and delivery events, remembering the chosen language, answering ordinary enquiries | Article 5(2)(f): processing necessary for the organiser's legitimate interests in secure operation and responding to enquiries, provided that users' fundamental rights and freedoms are not infringed |
| Recording acceptance of the terms and provision of the notice | Article 5(2)(c) for performance of the participation terms; Article 5(2)(ç) for fulfilling the duty to inform |
| Handling rights requests, fulfilling deletion duties and keeping the minimal deletion ledger | Article 5(2)(ç): compliance with legal obligations, including KVKK Articles 10 and 13 and requirements to record deletion operations |
| Keeping information necessary to establish, exercise or protect a specific right | Article 5(2)(e), limited to the necessary scope and relevant period |
| Record and fulfil the separate voluntary request for one launch email linked to a verified email address | Article 5(1): specific, informed and freely given consent for this purpose through a separate optional choice. Once withdrawn, the request is no longer used for sending |
| Record the choice, changes and withdrawal to establish the request's content and status | Article 5(2)(e): minimal history necessary to establish, exercise or protect rights, limited to the account period in section 5. The history does not permit sending after withdrawal |
Each ground applies to a specific purpose and only when its conditions are met. Free preregistration does not remove necessity and proportionality requirements. Acceptance of the terms, a read acknowledgement and an email code are not blanket processing consent. International transfers are governed separately and are described in section 4.
4. Recipients and international transfers
The organiser accesses data to operate preregistration. Resend receives the address and service email content to deliver codes and confirmation of account creation. Telegram is used for bot conversations and internal profile notifications to the organiser, including profile information and verified email; this also covers profiles submitted on the website. Contact form enquiries are forwarded through Google/Gmail and Telegram. Cloudflare provides website access and protection and processes web request information.
Messages to [email protected] pass through Cloudflare Email Routing and are forwarded to the organiser's Google/Gmail mailbox to receive and handle requests. These services process sender and recipient addresses, message content, attachments if sent, and technical delivery information. Data from requests is not used to create an advertising subscription.
The project's main infrastructure is on a NAS/VM in Turkey. Encrypted backups are created, including copies on the organiser's laptop. The countries of all copies and remote access locations have not been fully established.
These external services may process data outside Turkey. Using them for the website, emails and notifications creates regular data flows. MyTavs has not yet confirmed an applicable KVKK Article 9 transfer mechanism, a complete country list or recipients' contractual roles for these flows. This remains an unresolved issue concerning the lawfulness of international transfers. Accepting the terms, reading the notice, encryption and having the main database in Turkey do not replace a transfer mechanism. The explicit consent exception for incidental transfers under Article 9(6) is not a general basis for regular flows.
5. Retention and deletion
The active database is cleaned periodically, normally hourly. These periods are thresholds for the next cleanup, not promises of deletion at an exact second.
| Category | Implemented period |
|---|---|
| Account, associated role data, customer interest and document acknowledgements | 180 days from account creation; logging in again does not restart the period |
| Provider profile and separate legacy waiting list records | 180 days from the respective record's creation; account deletion may remove a profile earlier |
| Contact form enquiry | 90 days from creation |
| Registration stage events | 90 days |
| Temporary registration link | 1 day |
| Email code and login session | Code valid for 10 minutes; session up to 7 days; expired technical records are cleaned up |
| Telegram conversation working state | After 30 days without activity; technical incoming/outgoing bot and admin interface records are cleaned up 30 days after creation |
| Minimal deletion ledger | 1098 days from deletion, then the next cleanup; contains a technical link to the deleted record, not the retained profile |
| Launch email choice and the history of choices, changes and withdrawal | Removed from the active database with the account: at the next cleanup after 180 days from account creation, or earlier if the account is deleted. Changing the choice does not extend this period; withdrawal stops the request being used for sending |
| Account confirmation queue and minimal outcome record | Before email verification, a waiting record is kept within the account period. After email verification, the queue period is 24 hours. The address and content are encrypted and removed from the active queue after sending completes, attempts stop or cleanup after expiry. A minimal record containing the technical account identifier, times, status and attempt count remains to prevent duplicate sending and is removed with the account; the account period is not extended |
Account deletion removes associated records from the active database, including document acknowledgements, and ends access. A separate contact form enquiry is not linked to the account, has its own retention period and is not automatically removed with the account. Restoring an old backup requires applying the current deletion ledger.
Database cleanup frequency does not determine backup retention. Different backup sets use rotation by counts of 7 and 30 copies; these do not mean 7 and 30 days. A single calendar limit for all backup, release and recovery copies has not been established. Account deletion does not automatically remove delivered emails, Telegram cards or external provider copies. Their exact periods and deletion procedures have not been confirmed. Emails to [email protected] are held separately from the active database; the table's automatic periods do not apply to them, and a common retention period has not yet been established.
When all applicable processing grounds cease, data must be erased, destroyed or anonymised. This duty also covers backups and data transferred to recipients; the account deletion function's limitations do not remove it. Where data has been transferred to third parties, the controller must notify them and ensure the necessary actions under the applicable regulation. Deletion requests must be concluded within 30 days; retaining specific information under a continuing legal ground requires an explanation to the requester. Minimal records of deletion operations are retained for at least three years, rather than retaining the profile itself.
6. Cookies and browser storage
| Item | Purpose and period |
|---|---|
| mytavs_account cookie | Account login, up to 7 days; HttpOnly, SameSite=Lax, Secure on HTTPS. The session is revoked on logout or deletion |
| tavs_session cookie | Form protection and linking actions to the browser; server validity up to 24 hours from issuance; HttpOnly, SameSite=Lax, Secure on HTTPS |
| localStorage mytavs_language | ru, tr or en preference; no application expiry, kept until changed or cleared by the browser |
| sessionStorage tavs_provider_request, tavs_customer_request, tavs_feedback_request | Random identifiers preventing duplicate submissions; renewed after the relevant action, generally kept for the tab session |
The application does not write profile contents into these browser stores. The table describes application items. Cloudflare separately processes technical information and infrastructure logs for website access and protection; this table is not a complete inventory of the external provider's processing. The project's current code contains no advertising trackers. Blocking or clearing necessary cookies may interrupt login and forms.
7. Rights and request procedure
Under KVKK Article 11, you may:
- learn whether your data is processed and request information about that processing;
- learn the purposes and whether the data is used in accordance with them;
- learn the recipients in Turkey and abroad;
- request correction of incomplete or inaccurate data;
- request erasure or destruction under the conditions of Article 7 and notification of corrections or deletion to recipients;
- object to an adverse result arising from analysis carried out solely by automated systems;
- seek compensation for damage caused by unlawful processing.
You can withdraw your separate consent to one launch email at any time in your account or through [email protected]. Withdrawal ends use of the request for that email; it does not cancel necessary processing under another applicable ground. This interface does not request blanket international transfer consent, and withdrawal does not resolve the issue described in section 4.
Send requests to [email protected], including after account deletion. For an ordinary email request under the Communiqué, use an address previously supplied to MyTavs and recorded in its system. A formal request must be in Turkish and include your name, surname, request subject, notification address and the identification details required by Article 5(2) of the Communiqué; a signature is required for a written application. Include available contact details for the response.
If you cannot access your previous email or the record has been deleted, write to the same address to arrange a legally recognised submission method and proportionate identity verification. This does not exclude written requests or other methods provided by law, including KEP, a secure electronic signature or a mobile signature. The contact form also receives questions and requests; it is not the only way to exercise rights. Only necessary information is used to verify a requester; do not send a passport copy, banking or health documents through the ordinary contact form or Telegram. If additional verification is needed, a secure way to provide information will be arranged separately.
The controller must conclude a request as soon as possible and within 30 days of receipt at the latest. The final response is provided in writing or electronically; any refusal must state its reasons. Requests are free of charge except for additional costs expressly permitted by the tariff set by KVKK. If a response is late, insufficient or refuses the request, you may complain to the Board within 30 days of learning of the response and, in any event, within 60 days of the request to the controller. Rights to seek judicial remedies remain available.