Personal Data Policy

This policy explains personal data processing by Auvidi as data controller under Turkish Law 6698 (KVKK). It summarizes notice, data categories, purposes, legal bases, transfers, retention & destruction and data subject rights. It also explains how to exercise rights, application timelines and safeguards for domestic/cross-border transfers. Basic principles on platform security, access authorization and logging are stated; updates take effect when published.

KVKK Art. 10 Notice KVKK Art. 5/6 Legal Bases KVKK Art. 11 Rights

Summary

Data Controller
Auvidi Bilişim ve Müzik Teknolojileri A.Ş
Address
Kavakpınar Mah. İhsan Sok. No:18 D:7 Pendik/İstanbul
Effective Date
10.10.2025

Notice and scope

This text covers personal data processing on services, panel and support channels on auvidi.com and related subdomains. Auvidi is the data controller; suppliers and partners act as processors within contract scope and purpose. Scope includes web/panel interfaces, API endpoints, customer support and cookies/similar technologies. Processing follows KVKK Art. 10 notice and Art. 5/6 legal bases; data minimization is adopted. Traffic data under Law 5651 is retained for legal periods with integrity controls. Cross-border transfers use KVKK Art. 9 safeguards (adequacy, undertaking, board approval) where required.

VisitorsMembersArtists/LabelsProspective users

Data categories processed

  • Account: Name/title, contact, billing/info, verification records
  • Content: Tracks, ISRC/UPC, artist name, cover art, metadata
  • Technical: IP, device/client info, cookies, session/transaction logs
  • Payment: Payment provider tokens/transactions (card data not stored at Auvidi)
  • Support: Ticket/complaint records and correspondence
Special categories of personal data are generally not processed. Where law requires, limited processing with technical/administrative measures and explicit consent may apply.

Processing purposes

  • Service delivery, contract establishment/performance, identity verification
  • Finance, billing, collection and accounting
  • Security, fraud/abuse prevention and system logging (5651)
  • Customer support and operational communication
  • Fulfillment of legal obligations
  • Marketing/communication (only with explicit consent)

Legal bases (KVKK Art. 5/6)

  • Necessary for contract establishment/performance (Art. 5/2‑c)
  • Compliance with legal obligations (Art. 5/2‑ç)
  • Establishment, exercise or protection of a right (Art. 5/2‑e)
  • Legitimate interest (without prejudice to fundamental rights) (Art. 5/2‑f)
  • Explicit consent (where required)
  • Exceptions under Art. 6 for special categories

Transfer (domestic/cross-border)

Data may be transferred to service providers (hosting, CDN, payment, email, analytics) and stores/partners within processing purposes and with required security measures. Cross-border transfers apply adequate protection or undertaking/approval mechanisms under KVKK Art. 9.

  • Purpose limitation and data minimization
  • Processor agreements and confidentiality commitments

Retention and destruction

Records are retained within applicable law and limitation periods. Personal data is deleted, destroyed or anonymized at end of period. Destruction runs periodically and on request.

  • Account/transaction records: 10 years
  • 5651 traffic data: at least 10 years
  • Support correspondence: 10 years

Your rights (KVKK Art. 11)

As a data subject you have the right to learn whether data is processed, request information, question compliance with purposes, rectification, erasure/destruction/anonymization, learn third-party recipients, objection and compensation for damage.

How to apply

Send requests to admin@auvidi.com with information suitable for identity verification. Applications are concluded within 30 days at latest. Fees apply per KVKK and applicable tariffs where required.

You may also file complaints with the Personal Data Protection Authority. See our Privacy Policy and Cookie Policy for details.

Security measures

  • Encryption in transit and at rest
  • Access control and logging
  • Regular backups and integrity checks
  • Vulnerability/patch management
  • Two-factor authentication (2FA)
  • Least privilege and separation of duties
  • Regular penetration tests and vulnerability scans
  • Incident response plan and breach notification procedure

Updates and disputes

This policy may be updated; the revised text takes effect when published. Turkish law applies; courts in Istanbul (Pendik) have jurisdiction.