Data Protection Notice (KVKK)

Son güncelleme: 2026-09-10

This Notice is prepared under Article 10 of Turkish Personal Data Protection Law No. 6698 (“KVKK”) by the data controller operating the mehir.co service.

Data processed and purposes

  • Email: an HMAC digest for sign-in and, depending on the account feature, an encrypted address. Sending email passes the recipient address to the notification service.
  • Activity records: account, date and time, approval and security events. Account information such as a profile name may also be stored.
  • Document ID, hash and server record time: for looking up records and comparing file hashes.

Contract contents, titles and PDFs are processed on the server. Stored contract contents and PDFs are encrypted with server-managed keys. The server can decrypt them for authorized access and PDF generation. This is not end-to-end encryption. You can choose account storage or content deletion. Both parties must confirm saving their PDF copy before the owner separately confirms deletion.

Legal basis

Data is processed on the grounds of formation and performance of the contract, legitimate interest, and — for data indicating religious belief — your explicit consent.

Transfers

The service uses server infrastructure and a notification provider to send emails. Recipient addresses are processed to deliver invitations and sign-in emails. Information about providers and hosting can be requested through our contact channel.

Your rights (KVKK Art. 11)

You may exercise your rights to access, rectify, erase, object to processing, and others via the Data Subject Application Form.