Personal Data Protection Law (KVKK) Disclosure Text
Last Updated: August 19, 2026 (version 2)
> Translation notice: This English translation is provided for informational purposes only. This document implements a requirement specific to Turkish law (KVKK, Law No. 6698). The original Turkish text is the sole legally binding version; in the event of any conflict or inconsistency between this translation and the Turkish original, the Turkish text prevails. If you are located in the EEA/UK, see instead the Privacy Policy.
As Marryfix ("Marryfix"), acting as "Data Controller" under Law No. 6698 on the Protection of Personal Data ("KVKK"), we exercise the utmost care regarding the processing and security of your personal data.
1. Data Controller
Marryfix is not a legal entity/company; it is operated by an individual (natural person) developer. Your personal data is processed by the following data controller:
Data Controller: İsmail Nebi GENÇ
Address: Küçüksu Mahallesi, Rasathane Caddesi, No: 54/2, Üsküdar / İSTANBUL
Phone: +90 539 910 96 35
Email: support@marryfix.com
Pursuant to the relevant KVKK Principle Decision, the Explicit Consent Text and this Disclosure Text have been prepared as separate documents (see Explicit Consent Text). If the individual developer begins operating in the future through a virtual office or a legal entity, this section will be updated under the same versioning rule.
2. Purpose of Processing Personal Data
Your personal data (identity, contact, location, transaction security, visual and audio recordings, etc.) is processed for the following purposes:
- Provision of Marryfix services and completion of membership transactions.
- Enabling user matches and establishing communication.
- Carrying out information security processes and ensuring account security.
- Preventing abuse and fake accounts, protecting platform integrity.
- Preventing fake accounts and increasing profile trustworthiness through facial liveness and selfie verification.
- Investigating, evaluating, and resolving user complaints, reports, and disputes between users.
- Fulfilling legal obligations.
- Establishing, exercising, or defending a right (e.g. exercising our rights under the Terms of Use or applicable law).
- Managing customer satisfaction and support processes.
2b. Identity Data (First and Last Name)
Your first and last name information, collected during registration (membership creation), is processed within the following framework:
| Topic | Description |
|------|----------|
| Data processed | First and last name |
| Collection method | Electronically, through separate fields for first name and last name in the mobile app's registration form |
| Visibility on profile | The information you enter in the last name field is never shown to other users in the app interface; it is processed only for internal security and administrative purposes. The information you enter in the first name field may be displayed to other users on your profile, given the operation of the service. You are expected to enter only your first name in this field. |
| User responsibility | If you voluntarily enter your last name or full name into the first name field, this information may be visible to other members. This is not a system-level disclosure of the last name field; it is content you entered into the first name field. Marryfix cannot be held responsible for the visibility of user-entered content in the first name field — independent of the last name field — unless there is an intentional last name disclosure on our system's part. |
| Purposes of processing | (1) Account creation and completion of membership registration, (2) ensuring account security, preventing abuse and fake accounts, (3) investigating user complaints and disputes, (4) conducting customer support processes, (5) fulfilling legal obligations, (6) establishing, exercising, or defending a right |
| Legal grounds | KVKK Art. 5/2-(c) establishment or performance of a contract, Art. 5/2-(ç) legal obligation, Art. 5/2-(f) legitimate interest (provided it does not harm your fundamental rights and freedoms) |
| Retention | For as long as your account is active and for the periods prescribed by applicable legislation; deleted or anonymized after account deletion, subject to legal retention obligations |
| Transfer | Within the scope of Article 4 below; to hosting/server providers, customer support infrastructure, payment infrastructure (where relevant), legally authorized public bodies and judicial authorities — not transferred for marketing or profile-sharing purposes to other users |
2a. Biometric (Special Category) Personal Data
Your biometric data (facial recognition data), which is considered special-category personal data under KVKK Art. 6, is processed only on the basis of your explicit consent, within the following framework:
| Topic | Description |
|------|----------|
| Data processed | Facial recognition data (FaceId) generated during facial liveness detection and selfie verification |
| Data not stored | The selfie image is never stored |
| Reference retained | Only an opaque FaceId reference (`verifiedfaceref`) in our database |
| Processor | Amazon Web Services (AWS) — Amazon Rekognition |
| Data center | `eu-west-1` (Ireland — EU data center) |
| Legal safeguard | A signed GDPR Data Processing Addendum (DPA) under our AWS account |
| Deletion | Account deletion → `deleteEnrolledFace` → FaceId permanently deleted from Rekognition |
3. Method and Legal Basis for Collecting Personal Data
Your personal data is collected electronically through the mobile application, by automatic or partially automatic means. This collection activity is based on the following legal grounds set out in Articles 5 and 6 of the KVKK:
- Being explicitly provided for by law.
- Being directly related to the establishment or performance of a contract (the Membership Agreement).
- Being mandatory for the data controller to fulfill its legal obligation.
- Being mandatory for the data controller's legitimate interests, provided this does not harm your fundamental rights and freedoms.
- Your explicit consent (for special-category personal data and marketing activities).
Summary legal basis by data category:
| Data category | Example data | Primary legal basis |
|-----------------|---------------|----------------------|
| Identity | First name, last name | Establishment/performance of contract (Art. 5/2-c); legitimate interest — security and abuse prevention (Art. 5/2-f) |
| Contact | Email, phone | Establishment/performance of contract (Art. 5/2-c) |
| Transaction security | Session, device records | Legitimate interest — account security (Art. 5/2-f) |
| Biometric (face) | FaceId reference | Explicit consent (Art. 6) |
| Marketing | Communication preferences | Explicit consent (Art. 5/2-a) |
4. Transfer of Personal Data
Your personal data may be transferred, in accordance with Articles 8 and 9 of the KVKK, for the purposes stated above, to:
- Our business partners and service providers (hosting infrastructure, customer support infrastructure, payment infrastructure, AWS Amazon Rekognition — facial verification, `eu-west-1` region, etc.),
- Legally authorized public institutions and organizations,
- Judicial authorities.
Your first and last name information may be transferred to the recipient groups above for the purposes of account security, abuse prevention, dispute review, legal obligations, and protection of rights. Information you record in the last name field is not transferred to or shown to other users for profile or matching purposes. Since the first name field may be displayed on your profile, content you enter in that field (whether just a first name or a full name you entered) may be seen by other members; see item 2b — User responsibility above.
Biometric verification data is processed only in the AWS `eu-west-1` (Ireland) region. AWS acts as a data processor and is subject to data protection obligations under the GDPR DPA.
5. Your Rights Under KVKK (Article 11)
Pursuant to Article 11 of the KVKK, by applying to us, you have the right to:
- Learn whether your personal data is being processed,
- Request information if it has been processed,
- Learn the purpose of processing and whether it is used in accordance with that purpose,
- Know the third parties to whom it is transferred domestically or abroad,
- Request correction if it has been processed incompletely or incorrectly,
- Request its deletion or destruction within the framework of Article 7 of the KVKK,
- Object to a result that is to your detriment arising solely from the automated analysis of data processed exclusively through automated systems,
- Request compensation for damages if you have suffered harm due to unlawful processing.
6. How to Apply
To exercise your rights, you may submit your requests in writing (to the mailing address in §1 above), or via registered electronic mail (KEP), secure electronic signature, mobile signature, or by using the email address you have previously provided to us and that is registered in our system, sent to support@marryfix.com. For detailed information on the application procedure, identity verification, and response times, see the KVKK Application Process document.
7. Retention Periods and Technical Measures in Practice
Your personal data is retained only for as long as necessary for the purpose for which it is processed. The concrete retention periods and erasure methods applied to categories such as chat message, verification, and security audit data are listed in detail in `docs/privacy/DATARETENTIONPOLICY.md`; in summary:
- Chat message content is encrypted server-side with AES-256-GCM (with key management via AWS KMS) and permanently deleted 12 months after the room closes (90 days for recalled messages); if there is an active complaint/legal dispute, this period may be extended through a justified and reviewable "hold."
- Security audit logs are deleted after 12 months, and identity verification decision metadata after 24 months.
- When you delete your account, your identity is anonymized; associated test/compatibility/matching/contacts data is permanently deleted (KVKK Art. 7).