KVKK Data Protection Notice
Last updated: September 2026. Review our commitment to safeguarding your data, infrastructure isolation, and regulatory compliance.
1. Purpose of the Data Clarification Text
This text is prepared in accordance with the Law on the Protection of Personal Data No. 6698 ("KVKK") and international GDPR standards to inform our users and prospective clients regarding the processing, storage, and transfer of personal data by CoFlow Teknoloji A.Ş. ("Data Controller").
2. Processed Personal Data & Purpose
In the context of SaaS provisioning, customer accounting, and platform support, the following categories of data are processed:
- Identity Data: Full Name, National ID / Tax ID.
- Contact Data: Corporate Email, Phone Number, Invoicing Address.
- Customer Transaction Data: Subscription packages, consulting hours balance, invoices, payment receipts.
- Technical & Log Data: IP address, browser information, audit logs for authentication and security monitoring.
3. Technical & Operational Security Measures
CoFlow enforces an isolated multi-tenant container architecture. Customer business data (financial records, stock items, customer databases) resides in dedicated PostgreSQL databases and isolated Docker containers with zero cross-tenant access. All web communication is strictly encrypted using TLS 1.3 / 256-bit SSL.
4. Rights of the Data Subject
Under Article 11 of the KVKK, you are entitled to request information regarding whether your personal data is processed, request correction of incomplete/inaccurate data, and demand deletion or destruction under the statutory conditions. For any requests, please contact us at destek@coflow.com.tr.