Privacy Policy
1. Data Controller
This Privacy Policy has been prepared by Keysletter ("Company", "We", "Us"), which operates the email marketing platform accessible at keysletter.com. The Company acts as the Data Controller within the meaning of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR").
- Company Title: Keysletter
- Address: Osmanağa Mah. Söğütlüçeşme Cad. No:64/82 34714 Kadıköy, İstanbul
- Email: info@keysletter.com
- Phone: 0552 735 83 48
- Data Protection Officer: kvkk@keysletter.com
2. Scope
This Privacy Policy applies to all personal data collected through our website (keysletter.com), our email marketing platform, APIs, mobile applications (if any), and all related services. This policy covers data processing activities related to our customers, website visitors, email campaign recipients, and all other individuals whose personal data we process. By accessing or using our services, you acknowledge that you have read and understood this Privacy Policy.
3. Legal Basis
This Privacy Policy has been prepared in accordance with the following legislation:
- Law No. 6698 on the Protection of Personal Data (KVKK)
- Regulation on Deletion, Destruction or Anonymization of Personal Data
- Regulation on the Data Controllers' Registry (VERBİS)
- Law No. 6563 on the Regulation of Electronic Commerce
- Law No. 5651 on Internet Publications
- Turkish Commercial Code No. 6102
- Turkish Code of Obligations No. 6098
- EU General Data Protection Regulation (GDPR) — for users within the EEA
- Decisions and guidelines of the Personal Data Protection Authority (KVKK Board)
4. Personal Data Collected
We collect the following categories of personal data in accordance with the data minimization principle:
4.1 Identity Information
- Full name, company/organization name
- Tax identification number (for invoicing)
4.2 Contact Information
- Email address, phone number
- Billing address, company address
4.3 Account Information
- Username, encrypted password
- Profile picture (optional)
- Account preferences and settings
4.4 Usage and Technical Data
- IP address, browser type and version, operating system
- Pages visited, click data, session duration, referral source
- Device type, screen resolution, language preference
- Login timestamps, activity logs
4.5 Financial Data
- Payment method information (processed by our payment service provider; we do not store full card numbers)
- Billing and invoice history
- Subscription plan and usage details
4.6 Campaign and Subscriber Data
- Email lists uploaded by the user (subscriber names, email addresses, custom fields)
- Campaign content, templates, and sending history
- Campaign analytics: open rates, click rates, bounce rates, unsubscribe data
5. Purposes of Data Processing
Your personal data is processed for the following purposes in accordance with Article 5 and Article 6 of KVKK:
- Establishing and performing the service agreement between you and Keysletter
- Providing, operating, and maintaining our email marketing platform
- User account creation, authentication, and authorization management
- Processing payments and billing operations
- Responding to support requests and communicating about your account
- Ensuring platform security, preventing fraud, and detecting unauthorized access
- Analyzing usage trends to improve and develop our services
- Fulfilling legal and regulatory obligations (tax, commercial records, etc.)
- Sending service notifications and platform updates (not marketing)
- Compliance with anti-spam regulations and IYS (Message Management System) requirements
- Resolving disputes and enforcing our agreements
6. Methods of Collection and Legal Basis
Personal data is collected through the following methods:
- Registration and account creation forms on our website
- Communication via email, phone, or support tickets
- Cookies and similar tracking technologies
- API integrations and third-party login providers (Google OAuth)
- Payment service providers (for financial data)
- Automated systems (server logs, analytics)
The legal bases for processing your data under KVKK Article 5(2) are:
- Explicit Consent (m.5/1): For marketing communications and optional analytics
- Contractual Necessity (m.5/2-c): Processing necessary for the performance of the service agreement
- Legal Obligation (m.5/2-ç): Tax, commercial, and regulatory record-keeping requirements
- Legitimate Interest (m.5/2-f): Platform security, fraud prevention, service improvement — provided your fundamental rights are not harmed
- Public Disclosure (m.5/2-d): Data you have made publicly available
7. Data Sharing and Transfer
We do not sell, rent, or trade your personal data. In accordance with Articles 8 and 9 of KVKK, your personal data may be shared with the following parties only to the extent necessary:
- Payment Service Providers: For processing subscription payments (PCI DSS compliant)
- Cloud Infrastructure Providers: For hosting and data storage services
- Email Delivery Services: SMTP providers for campaign delivery
- Analytics Providers: For understanding usage patterns (anonymized where possible)
- Legal Authorities: When required by law, court order, or regulatory authorities
- IYS (Message Management System): For commercial electronic message consent management as required by Turkish law
All third-party service providers are contractually obligated to protect your data and process it only for the specified purposes. We conduct due diligence on all data processors and require them to maintain appropriate security measures.
8. International Data Transfers
In accordance with KVKK Article 9, your personal data may be transferred to countries outside Turkey only under the following conditions:
- Transfer to countries deemed to have adequate protection by the KVKK Board
- Where adequate protection is not available, with your explicit consent or where the data controllers in both countries provide sufficient written guarantees and the Board grants authorization
- Binding Corporate Rules or Standard Contractual Clauses approved by the Board
Some of our service providers (cloud hosting, analytics) may process data in the European Economic Area (EEA) or other jurisdictions. In such cases, we ensure GDPR-compliant data processing agreements and Standard Contractual Clauses are in place.
9. Data Retention Periods
We retain your personal data only as long as necessary for the purposes for which it was collected, or as required by applicable laws. Specific retention periods are as follows:
- Account Data: Throughout the duration of your account, plus 3 years after account closure
- Financial/Invoice Data: 10 years from the transaction date (Tax Procedure Law No. 213 and Turkish Commercial Code No. 6102)
- Campaign Data: Throughout the duration of your account, deleted within 30 days of account closure upon request
- Log/Security Data: 2 years (Law No. 5651 and related regulations)
- Cookie Data: Maximum 13 months from the date of consent
- Commercial Message Consent Records: Throughout the consent period, plus 3 years after withdrawal (Law No. 6563)
- Support Tickets: 3 years after ticket resolution
Upon expiration of the retention period, personal data is deleted, destroyed, or anonymized in accordance with the Regulation on Deletion, Destruction or Anonymization of Personal Data.
10. Cookie Policy
Our platform uses cookies and similar technologies. Cookies are small text files stored on your device that help us provide you with a better experience.
10.1 Essential Cookies
Required for the basic operation of the platform. These cannot be disabled.
- Session management and authentication
- Security tokens (CSRF protection)
- Language and culture preferences
- Cookie consent preferences
10.2 Analytics Cookies
Help us understand how visitors interact with our platform.
- Page views and navigation paths
- Feature usage statistics
- Error and performance monitoring
10.3 Preference Cookies
Remember your settings for a personalized experience.
- Dashboard layout preferences
- Notification settings
- Recently used features
You can manage your cookie preferences through your browser settings. Please note that disabling essential cookies may affect the functionality of our platform.
11. Data Security Measures
In accordance with KVKK Article 12, we implement the following technical and administrative measures to protect your personal data:
Technical Measures
- SSL/TLS encryption for all data in transit (HTTPS)
- AES-256 encryption for sensitive data at rest
- Password hashing with industry-standard algorithms (bcrypt)
- Web Application Firewall (WAF) and DDoS protection
- Rate limiting and brute-force protection on authentication endpoints
- Regular security patches and updates
- Intrusion detection and prevention systems (IDS/IPS)
- Regular automated backup procedures
- CSRF, XSS, and SQL injection protection
Administrative Measures
- Access control policies based on the principle of least privilege
- Employee confidentiality agreements and regular privacy training
- Personal data processing inventory and activity records
- Regular internal security audits
- Data processor agreements with all third parties
- Incident response and data breach notification procedures
12. Data Breach Notification
In the event of a personal data breach, we will notify the Personal Data Protection Authority (KVKK Board) within 72 hours of becoming aware of the breach, as required by KVKK Article 12(5). If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you as soon as possible through the contact information in your account. The notification will include the nature of the breach, the categories and approximate number of affected individuals, the potential consequences, and the measures taken or proposed to address the breach.
13. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete such data immediately. If you believe that we have inadvertently collected data from a minor, please contact us at kvkk@keysletter.com.
14. Your Rights under KVKK
In accordance with Article 11 of KVKK, you have the following rights regarding your personal data:
- Right to learn whether your personal data is being processed
- Right to request information about the processing if your data has been processed
- Right to learn the purpose of processing and whether they are used in accordance with their purpose
- Right to know the third parties to whom your data is transferred domestically or abroad
- Right to request correction if your data is incomplete or inaccurate
- Right to request deletion or destruction under the conditions specified in Article 7
- Right to request that corrections, deletions, or destructions be notified to third parties to whom data was transferred
- Right to object to any result arising against you from the analysis of processed data exclusively through automated systems
- Right to claim compensation for damages arising from unlawful processing
15. Your Rights under GDPR
If you are located within the European Economic Area (EEA), you additionally have the following rights under the General Data Protection Regulation:
- Right of Access (Art. 15): Obtain confirmation and a copy of your personal data being processed
- Right to Rectification (Art. 16): Have inaccurate personal data corrected without undue delay
- Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten")
- Right to Restriction (Art. 18): Request restriction of processing in certain circumstances
- Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing
- Right Regarding Automated Decisions (Art. 22): Not to be subject to decisions based solely on automated processing
- Right to Lodge a Complaint: Lodge a complaint with a supervisory authority (in Turkey: KVKK Board)
16. How to Exercise Your Rights
To exercise any of the rights mentioned above, you may submit your request using one of the following methods in accordance with the Communiqué on Procedures and Principles of Application to the Data Controller:
- Email: Send your signed request to kvkk@keysletter.com
- Registered Mail: Send via registered electronic mail
- Written Application: Submit a signed petition to our company address
Your request must include your identity information (name, surname, Turkish ID number for Turkish citizens or passport/ID number for foreigners), contact details, the subject of your request, and supporting documents if applicable. We will respond to your request free of charge within 30 days at the latest. If the request requires additional costs, we may charge a fee in accordance with the tariff determined by the KVKK Board.
17. Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or our services. When we make material changes, we will notify you through a prominent notice on our platform, via email, or both at least 30 days before the changes take effect. The "Last Updated" date at the bottom of this page indicates when this policy was last revised. We encourage you to review this policy periodically.
18. Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
- General Inquiries: info@keysletter.com
- Data Protection Requests: kvkk@keysletter.com
- Phone: 0552 735 83 48
- Address: Osmanağa Mah. Söğütlüçeşme Cad. No:64/82 34714 Kadıköy, İstanbul
You may also file a complaint with the Personal Data Protection Authority (KVKK) at www.kvkk.gov.tr if you believe your rights have been violated.
Last Updated: April 16, 2026