As BNN YAZILIM DANIŞMANLIK DIŞ TİCARET LİMİTED ŞİRKETİ (hereinafter referred to as the “Company”), we respect and attach importance to the confidentiality of private life. We would therefore like to inform you, within the scope of Law No. 6698 on the Protection of Personal Data (hereinafter referred to as “KVKK”), about your rights regarding the use and protection of your personal data.
§ 01
Identity of the Data Controller
We, BNN YAZILIM DANIŞMANLIK DIŞ TİCARET LİMİTED ŞİRKETİ (hereinafter referred to as the “Company”), hereby notify you that we process your personal data in our capacity as data controller within the scope of Law No. 6698 on the Protection of Personal Data (hereinafter referred to as “KVKK”) and other relevant legislation.
§ 02
Categories of Personal Data Processed
In accordance with the KVKK and other relevant legislation, your personal data in the categories set out below will be processed for the purposes and on the legal grounds specified in this Privacy Notice under Law No. 6698 on the Protection of Personal Data.
Identity
03- Name and Surname
- Turkish ID Number (TCKN)
- Customer ID
Contact
04- E-mail Address
- Telephone Number
- Business Address
- Social Media Accounts
Customer Transaction
03- Call Center Records
- Order Information
- Message Records
Marketing
04- Site Usage Information (Cookies)
- Survey
- Form
- Commercial Communications
Transaction Security
07- Device Operating System and Version
- Device Type
- Device ID
- Hardware Model
- IP Address
- User Transaction Logs
- Password Information
Finance
05- Payment Records and Card Information Depending on the Payment Method
- IBAN Information
- Tax Certificate
- Tax Number
- Signature Circular
Legal Transaction
04- Information in Case Files in the Event of a Dispute
- Formal Notices
- Information in Correspondence with Judicial and Administrative Authorities
- Contracts
Professional Experience
03- Occupation Information
- Employment History
- Professional Experience Information
Visual Records
01- Profile Photo
§ 03
On Which Legal Grounds and for Which Purposes Your Personal Data Will Be Processed
Pursuant to items a), b) and c), your personal data will be processed by us without your explicit consent. However, your personal data listed in item d) may be processed by us only on condition that you give your explicit consent of your own free will.
On the legal grounds of “Being Provided for by Law” and “Being Necessary for the Data Controller to Fulfill Its Legal Obligations” pursuant to KVKK Art. 5(2)(a) and 5(2)(ç), your data in the Identity, Contact, Transaction Security, Finance, Legal Transaction and Professional Experience categories will be processed for the purposes of:
- Carrying out storage and archiving activities as required by the relevant legislation
- Carrying out finance and accounting operations
- Conducting activities in compliance with the law as required by the relevant legislation
- Providing information to public institutions and organizations
- Carrying out information security processes
- Following up and conducting legal affairs
On the legal ground of “Being necessary because it is directly related to the establishment and performance of an agreement between you and us” pursuant to KVKK Art. 5(2)(c), your data in the Identity, Contact, Finance, Professional Experience and Legal Transaction categories will be processed for the purposes of:
- Carrying out service sales processes as BNN YAZILIM DANIŞMANLIK DIŞ TİCARET LİMİTED ŞİRKETİ
- Carrying out after-sales support services
- Carrying out service operation processes
- Carrying out communication activities
- Carrying out storage and archiving activities.
On the legal ground of “Data processing being necessary for the legitimate interests of the data controller, provided that this does not harm the fundamental rights and freedoms of the data subject” pursuant to KVKK Art. 5(2)(c), your data in the Identity, Contact, Transaction Security, Customer Transaction, Visual Records and Professional Experience categories will be processed for the purposes of:
- Ensuring the security of the data controller’s operations
- Performing identity verification procedures
- Carrying out audit activities
- Making the website functional
- Performing professional qualification verification procedures
- Ensuring the legal, technical and commercial business security of the data subjects with whom there is a business relationship.
On the legal ground of “your having given explicit consent” pursuant to KVKK Art. 5(2)(a), your marketing data may be processed for the following purposes, provided that you give your explicit consent in the “Explicit Consent Text” presented to you in addition to this privacy notice.
- Marketing: Provided that you give your consent of your own free will, your personal data may be processed for the purposes of contacting you within the scope of marketing activities relating to our products and services, sending commercial electronic messages, conducting surveys and satisfaction studies, and collecting cookies for advertising purposes via the website.
§ 04
To Whom and for What Purpose Your Processed Personal Data May Be Transferred
We transfer the data we process as data controller only domestically, for the purposes and to the groups of persons specified below.
Our Accountants
01Carrying out finance and accounting operations.
Data transferred
- Your Identity Data
- Your Finance Data
- Customer Transaction
- Your Contact Data
Our Lawyers
02Conducting and following up legal affairs and transactions.
Data transferred
- Your Identity Data
- Your Legal Transaction Data
- Your Customer Transaction Data
- Your Contact Data
Authorized Institutions and Organizations
03Conducting activities in compliance with the legislation, Providing information to authorized persons, institutions and organizations.
Data transferred
- Your Identity Data
- Your Finance Data
- Your Contact Data
- Your Professional Experience Data
- Your Transaction Security Data
Our Suppliers/Business Partners
04Planning organizational processes, Carrying out service sales processes, Carrying out after-sales support services, Carrying out service operation processes, Carrying out additional service sales processes, Carrying out advertising/campaign processes, Performing marketing activities.
Data transferred
- Your Identity Data
- Your Finance Data
- Your Contact Data
- Your Customer Transaction Data
- Your Marketing Data
§ 05
By Which Methods Your Personal Data Is Collected
Your personal data is obtained, on the basis of the legal grounds set out in section (3) of this text and in order to fulfill the stated purposes, by automated means and, in some cases, by non-automated means, orally, in writing or electronically. These methods are as follows:
- 01Completion of forms by the data subject
- 02Sending of e-mail messages
- 03Contact by telephone call
- 04Visits to the website (collection of cookies)
- 05Registration via the website
- 06Contact via messages
- 07Contact via social media platforms
- 08Your having made your data public on other platforms
- 09Notes taken manually during meetings
§ 06
Your Rights under Article 11 of the KVKK
Under KVKK Art. 11 and the relevant legislation, you have the following rights with regard to your personal data:
- a
To learn whether personal data is processed,
- b
To request information in this regard if personal data has been processed,
- c
To learn the purpose of the processing of personal data and whether it is used in accordance with its purpose,
- d
To know the third parties to whom personal data is transferred domestically or abroad,
- e
To request the rectification of personal data if it has been processed incompletely or inaccurately,
- f
To request the erasure or destruction of personal data within the framework of the conditions set out in Article 7 of the KVKK,
- g
To request that the operations carried out pursuant to subparagraphs (e) and (f) be notified to the third parties to whom personal data has been transferred,
- h
To object to the occurrence of a result to your detriment through the analysis of the processed data exclusively by means of automated systems,
- ı
To request compensation for the damage in the event that you suffer damage due to the unlawful processing of personal data.
§ 07
Exercise of Statutory Rights Relating to Personal Data
In order to exercise your rights regarding your personal data, you may submit your requests to us, in accordance with the “Communiqué on the Procedures and Principles of Application to the Data Controller”, through the channels below or by other methods to be determined by the Board in the future.
- 1
With your own handwritten signature and a valid identity document, in person or through a notary public
Altunizade Kısıklı Cad. Tekin Ak İş Merkezi, D:No:3 Daire:9, 34662 Üsküdar/İstanbul
The envelope must be marked “Application under the KVKK”
- 2
Via your own registered e-mail (KEP) address
“Application under the KVKK” must be written in the subject line of the e-mail
- 3
By e-mail bearing a secure electronic signature or mobile signature
“Application under the KVKK” must be written in the subject line of the e-mail
- 4
Via the e-mail address registered in our system
“Application under the KVKK” must be written in the subject line of the e-mail
If you are applying on behalf of another person, you must enclose with your application, together with your own identity information: (a) a civil registry record or the relevant document showing your relationship with, and your authority over, the person of whom you are the parent or guardian, (b) in other cases, a copy of the power of attorney by which you have been specifically authorized.
Pursuant to the “Communiqué on the Procedures and Principles of Application to the Data Controller”, the application must contain the following information:
- (a) Name, surname and, if the application is made in writing, signature,
- (b) For citizens of the Republic of Türkiye, the Turkish identity number; for foreigners, nationality, passport number or, if any, identity number,
- (c) Place of residence or business address for service of notifications,
- (d) If any, e-mail address, telephone and fax number for notifications,
- (e) Subject of the request.
§ 08
Changes and Updates
This privacy notice has been prepared within the scope of Law No. 6698 on the Protection of Personal Data and other relevant legislation. Necessary changes may be made to the said privacy notice in line with changes in the relevant legislation and/or in the Company’s personal data processing purposes and policies. In the event of changes, our new texts will be made available to you through appropriate media.
You can access the most up-to-date version of the Privacy Notice at https://docvivo.com.
§ 09
Data Security
SSL
The SSL used on Docvivo servers ensures that data between our users and the system is encrypted and transferred securely. The encryption used is the same as the encryption standards used by banks.
User Access
Unless invited by you, no one is given access to your company account. Only in the event of a technical or system failure do Docvivo personnel authorized with your permission access your relevant data for support purposes.
User Passwords
Users are expected to create strong passwords, and users themselves are responsible for the confidentiality of the passwords they create. In the event of multiple incorrect login attempts, the user account is blocked. Sessions that remain open for a long time are closed automatically.
Physical Security, Network Security and Firewall
The technological infrastructure of the Application and the data center in which we store our users’ data are hosted by ministry-approved data centers domestically and abroad.
Data Sharing
Data is not shared without your approval or with business partners that do not have adequate security.
Data Backup
Your data is backed up daily as a safeguard against possible technical problems.
Your data is safer with Docvivo
With Docvivo, your data is not stored on your computer. Thus, in the event that your computer breaks down, is stolen or is lost, your data remains completely safe.
Where you need to share your data with any person inside or outside your company, instead of sending it by e-mail or CD, you can provide much more secure access to your data by assigning the persons with whom you wish to share your data as users.
§ 10
Collection and Use of Health Data
Docvivo Health collects and processes users’ health data for the following purposes:
- Viewing Personal Health Records
- Enabling users to view their personal health records.
- Presenting Health Information on a Single Screen
- Providing users with easy access by presenting all health information on a single screen.
- Creating and Managing Health Requests
- Enabling users to create and manage their health requests.
- Tracking Daily Health Records
- Enabling users to track their daily health records.
- Viewing Scheduled Medical Appointments
- Enabling users to view their scheduled medical appointments.
The health data collected is used solely for the purpose of providing the services specified above and is not shared with third parties without the users’ explicit consent.
§ 11
Use of Meta Platform Data
This platform processes the “Platform Data” provided via Meta (Facebook/Instagram) (e.g. Page/IG account ID, profile name and picture, message contents, Page list, permission tokens) solely for the purpose of message management and customer support for assets belonging to our customers.
- Purposes
- Authentication, listing the Pages/IG accounts you manage, displaying and replying to DM/Messenger conversations in the CRM, presenting basic engagement metrics (aggregated and de-identified).
- Prohibited Uses
- There is no bulk/broadcast messaging, no unsolicited commercial communication, no profiling that allows re-identification, and no sale/dissemination.
- Retention
- We retain it for the minimum period necessary to provide the service; it is deleted/anonymized upon the customer’s request or when the agreement ends.
- Access
- Only authorized personnel and contracted data processors (hosting/infrastructure, monitoring and security providers) may access it.
- Compliance
- We comply with the relevant rules, including the Meta Platform Terms, the Developer Policies and the 24-hour messaging window.
§ 12
Meta Platform Data Deletion Request
To request the deletion of your Platform Data obtained via Facebook/Instagram, you may use one of the following methods:
- To [email protected] with the subject “Meta Data Deletion Request”.
After your request is received, the relevant data is deleted within 30 days at the latest, subject to contractual and legal obligations, and you are notified by e-mail.
§ 13
Data Processors / Transfers / Retention Period
- Data Processors
- Hosting (e.g. cloud infrastructure), e-mail/SMS providers, logging/monitoring, security. The list is shared upon request.
- Transfer
- If a transfer abroad is required, contractual safeguards and the requirements of the applicable legislation are ensured.
- Messenger/IG DM contents
- For the duration of the service agreement and for a max. of 90 days for operational record-keeping purposes; thereafter deleted/anonymized.
- Access tokens
- Validity period + short-term log for security.
§ 14
User Rights & Contact
- Rights (access, rectification, erasure, objection) + one-click contact
- [email protected]
- Data controller trade name/address
- BNN YAZILIM DANIŞMANLIK DIŞ TİCARET LİMİTED ŞİRKETİ / Altunizade Kısıklı Cad. Tekin Ak İş Merkezi, D:No:3 Daire:9, 34662 Üsküdar/İstanbul
§ 15
Cookies/Authentication and Security
Session cookies are used solely for authentication and security; cookies for marketing purposes are subject to explicit consent. Application traffic is encrypted with TLS; access is subject to authorization and logging (audit log).

