Privacy Policy

Kritm values the security and privacy of your personal data. Collected information is used for providing services, offering support, and fulfilling legal obligations. Your data is stored securely and shared only with authorized third parties. By using our services, you agree to these privacy terms.

Last Updated: 26.07.2025

This Privacy Policy explains the processes of collecting, using, and protecting personal data you share while using the cloud and software services offered by Kritm. Kritm operates within the scope of the Personal Data Protection Law No. 6698 ("KVKK") and the European General Data Protection Regulation ("GDPR").

Information We Collect

As Kritm, we collect the following personal data to provide our services:

  • First name, last name
  • Email address
  • Phone number
  • Turkish ID Number
  • Support messages and communication records
  • Payment information (e.g., credit card, billing information)
  • IP address and session information

Purposes of Data Collection

Your personal data may be used for the following purposes:

  • Account creation and user verification
  • Responding to support requests
  • Providing and improving our services
  • Processing payment transactions (PayTR)
  • Sending email notifications and system messages
  • Security auditing and error management
  • Fulfilling legal obligations

Legal Basis (KVKK vs GDPR)

Under KVKK: Data processing activities are carried out with legal bases such as explicit consent, establishment and performance of contract, fulfillment of legal obligations. Under GDPR: Kritm generally bases data processing activities for EU citizen users on the following grounds:

  • Explicit consent (Art. 6(1)(a))
  • Performance of contract (Art. 6(1)(b))
  • Legitimate interest (Art. 6(1)(f))
  • Legal obligation (Art. 6(1)(c))
  • Differences:
  • GDPR provides broader rights (e.g., data portability, objection to automated processing).
  • In KVKK, the obligation to notify the data controller is less detailed.
  • If you are under GDPR scope, you have some additional obligations (e.g., DPO appointment, clear data mapping, export contracts, etc.).

Necessity Assessment: Turkey-based Kritm is primarily subject to KVKK. However, if serving EU citizens or there is access from the EU, GDPR compliance is also required.

Data Retention Period

Your personal data is retained for the period required by legal obligations or for a reasonable period after the service ends. Examples:

  • Payment records – 10 years
  • Support messages – 3 years
  • Login logs – 1 year

Sharing with Third Parties

Your data is shared with the following third parties only to the extent necessary:

  • Payment processing - PayTR
  • Email sending
  • Legal obligations - Official authorities (upon request)

User Rights

Under KVKK and/or GDPR, you have the following rights:

  • Access to your data
  • Request correction of data
  • Request deletion ("right to be forgotten")
  • Object to processing
  • Port your data (GDPR)
  • File complaints (KVKK – KVKK Board, GDPR – relevant country's data protection authority)

Security

Kritm implements measures such as TLS/HTTPS, encryption, firewalls, and limited access principles to protect your data. We also proactively monitor security vulnerabilities with services like Sentry.

Payment Information and Card Storage Policy

Credit card information used in payments made through our website is processed through a third-party service provider that provides secure payment infrastructure and is protected within the framework of PCI-DSS (Payment Card Industry Data Security Standard) compliance. Your card information is never directly viewed, recorded, or stored by us.

With the explicit consent of users, card information can be securely stored by tokenizing (encrypting and replacing with unique representatives) for the convenience of future payments. This storage process is only carried out by the payment infrastructure provider, and the complete card information and security codes (CVV) are not accessible by us.

Users can delete or change stored card information at any time through the system. All payment transactions are carried out in accordance with current data security protocols and are regularly audited.

Commercial Communication

Your collected email address may be used for the execution of services (billing, payment notifications, security alerts, support communication). No additional consent is required for sending such mandatory emails.

If the user provides explicit consent, Kritm may send commercial electronic communications containing campaigns, promotions, discounts, and announcements. This consent is recorded by the user through the Message Management System (İYS).

Users may withdraw their consent for commercial communications at any time. Commercial communication is stopped after the withdrawal notification.

Contact

For any questions or requests regarding your privacy, you can reach us at the following address:

info@kritm.com

Policy Updates

This policy may be updated from time to time. Updates take effect when published on our website. Important changes may be notified via email.