Introduction
This privacy policy explains the processing methods and purposes of personal data collected by the Cosyworker mobile application (hereinafter referred to as the "Application") and information about user rights in accordance with the Personal Data Protection Law No. 6698 ("PDPL/KVKK"), the Law No. 5651 on Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications, and other relevant legislation provisions.
The Application is available for download on Google Play Store and Apple App Store, and is a platform that enables users to discover workspaces, participate in events, and build communities.
By registering for the Application or starting to use the Application, you are deemed to have accepted the terms included in this privacy policy. If you do not accept this policy, we kindly request that you refrain from using the Application.
1. Data Controller
Within the scope of the disclosure obligation under Article 10 of the PDPL, the information regarding the data controller is as follows:
Name: Kudret Yılmaz
Address: Istanbul, Turkey
Email:
[email protected]
Within the scope of the PDPL, the data controller is the natural person who determines the purposes and means of processing personal data, and is responsible for the establishment and management of the data recording system. Kudret Yılmaz is responsible for all personal data processing activities of the Cosyworker application.
2. Personal Data Processed and Processing Purposes
The following personal data categories are processed within the scope of the Application for the stated purposes:
| Data Category | Source | Purpose |
|---|
| Name - Surname | Direct user | User identification, account management, profile display |
| Date of Birth | Direct user | Age verification, age-based recommendations |
| Gender | Direct user | Personalized experience |
| Profile Photos | User upload | Profile display, social interaction |
| Location Information | Device (real-time) + user input (saved) | Nearby venue listing, map display, location-based recommendations |
| Occupation Information | Direct user | Profile enrichment, community matching |
| Email Address | Direct user (required) | Registration, verification, communication, notifications |
| Device IDs | Automatic collection | Application analytics (Amplitude), push notifications, error tracking (Sentry) |
| Usage Data | Automatic collection | In-app interaction analysis, click history, feature improvement |
| CosyAI Chat Data | Direct user (CosyAI interaction) | Personalized AI responses, socialization task tracking, venue/event recommendations |
| CosyAI Learned Preferences | Automatic processing (CosyAI analysis) | Personalized recommendation and task generation, user experience improvement |
| Payment/Transaction Data | App Store / Play Store | In-app purchase verification, transaction history |
| Visual/Media Content | User upload | Venue photos/videos, user-generated content |
Special Category Data Declaration: Our application does not collect or process special category personal data as defined in Article 6 of the PDPL (race, ethnic origin, political opinion, philosophical belief, religion, sect, clothing, association-foundation-union membership, health, sexual life, criminal conviction, biometric and genetic data).
3. Legal Basis for Processing Personal Data
Your personal data is processed based on the following legal grounds under Articles 5 and 6 of the PDPL:
• Explicit Consent (PDPL Article 5/1): Your personal data such as name-surname, email, gender, occupation, date of birth, and profile photo are processed by obtaining your explicit consent for the purpose of registering in the application and fully benefiting from the services offered.
• Establishment and Performance of Contract (PDPL Article 5/2-c): Your data necessary for the establishment of the membership agreement and provision of services is processed within the scope of contract performance.
• Legal Obligation (PDPL Article 5/2-ç): Your data is processed within the scope of legal obligations such as traffic data retention obligations under Law No. 5651 and obligations under the Law No. 6563 on the Regulation of Electronic Commerce.
• Legitimate Interest (PDPL Article 5/2-f): Your data may be processed for purposes of ensuring application security, error tracking (Sentry), improving user experience (Amplitude), and fraud prevention, provided that it does not harm your fundamental rights and freedoms.
• Data Made Public (PDPL Article 5/2-d): Personal data that the user has made public themselves (for example, information made publicly available on the profile page) may be processed.
• CosyAI Explicit Consent (PDPL Article 5/1): Chat history, learned preferences, and context data processed within the scope of the CosyAI artificial intelligence assistant are processed based on explicit consent separately obtained from the user upon the first use of CosyAI. This consent is required for CosyAI to generate personalized responses, create socialization tasks, and improve recommendation quality.
4. Method of Data Collection
Your personal data is collected through the following methods:
• Directly from User: Information directly entered by the user through registration forms, profile editing screens, and in-app forms (name-surname, email, occupation, date of birth, gender, profile photo, etc.).
• Automatic Collection: Data automatically collected from your device during application use (device IDs, usage data, error logs, session information, IP address, etc.).
• Third-Party Platforms: Data related to in-app purchase transactions made through Google Play Store and Apple App Store (transaction verification information).
• Device Permissions: Data accessed when the user grants permission from device settings:
- Location permission: For listing nearby venues
- Camera/gallery permission: For uploading profile photos and venue images
- Notification permission: For sending push notifications
• CosyAI Interactions (corporate users only): Messages collected from conversations with the CosyAI artificial intelligence assistant and automatically inferred preference information. This data is collected during the user's active use of CosyAI.
5. Data Transfer Recipients
5.1 Domestic Transfer:
Your personal data may be shared domestically with the following parties in accordance with Article 8 of the PDPL, as required by the service:
• Legal advisors and financial consultants (for fulfillment of legal obligations)
• Business partners (for service delivery within the scope of contracts)
5.2 International Transfer:
In accordance with Article 9 of the PDPL, your personal data is shared with the following international service providers. These transfers are carried out within the scope of your explicit consent or other conditions stipulated in the PDPL:
| Service Provider | Country | Purpose | Shared Data |
|---|
| Amazon Web Services (AWS) | USA/EU | Cloud hosting and data storage | All stored data |
| Hetzner | Germany/EU | Cloud hosting and data storage | All stored data |
| Amplitude | USA | User behavior analysis and performance monitoring | Device IDs, usage data, anonymized interaction events |
| Meta SDK (Facebook) | USA | Ad optimization and campaign performance | Device IDs, ad interaction data |
| Sentry | USA | Error tracking and crash reporting | Device IDs, error logs, device metadata |
| Google Gemini API | USA | AI chat response generation (CosyAI) | CosyAI chat messages, user context information (corporate users only) |
| Google Play / Apple App Store | USA | In-app purchase processing | Payment/transaction data |
Necessary technical and administrative measures are taken within the scope of Article 12 of the PDPL in data transfers with these service providers, and data processing agreements are executed.
5.3 Transfer to Legal Authorities:
In case of duly requests by legally authorized public institutions, courts, or law enforcement agencies, your personal data may be transferred to the relevant authorities within the framework of the PDPL and other legislation.
6. Hosting Provider Responsibility (Law No. 5651)
Cosyworker holds the position of "hosting provider" within the scope of the Law No. 5651 on Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications.
In this context:
• Cosyworker hosts content created by users (venue reviews, event descriptions, photos, profile information, etc.) and has no obligation to pre-screen such content for legal compliance.
• Users are personally responsible for all content they upload to the application. Content that is unlawful, defamatory, violates personal rights, or infringes upon the rights of third parties may not be uploaded.
• Upon detection of unlawful content, the relevant content is removed or access is blocked in accordance with Article 5 of Law No. 5651.
• Reporting and notification mechanism: Users who detect unlawful content can report through the in-app reporting system or via
[email protected]. Reports are evaluated within 72 hours at the latest.
7. In-App Purchases and Payment Data
Payments for paid services offered in the Cosyworker application (advertising packages, premium features, etc.) are processed entirely through Google Play Store and Apple App Store infrastructure.
In this context:
• Cosyworker does not collect or store users' credit card numbers, bank account information, or other direct payment information.
• Payment transactions are carried out within the framework of Google and Apple's own payment systems and security protocols.
• Cosyworker only receives transaction verification information (purchase confirmation, transaction ID, purchase date) to ensure service delivery.
• Refund requests are evaluated within the framework of the refund policies of the relevant application store (Google Play Store or Apple App Store). For refund requests, please refer to the support page of the relevant store.
• For privacy policies regarding payment data, we recommend reviewing the privacy policies of Google (https://policies.google.com/privacy) and Apple (https://www.apple.com/legal/privacy/).
7A. CosyAI Data Processing
This section contains specific provisions regarding personal data processed within the scope of the CosyAI artificial intelligence assistant. CosyAI is offered exclusively to corporate users and the provisions of this section apply only to corporate users who use the CosyAI service.
7A.1 Collected Data
The following data categories are collected and processed within the scope of the CosyAI service:
• Chat History: All messaging content from the user's conversations with CosyAI.
• Learned Preferences: Preferences, interests, and behavioral patterns automatically inferred by CosyAI from user interactions.
• Task and Progress Data: Socialization tasks assigned to the user, completion statuses, and progress information.
• Context Data: User profile information and interaction context used for personalized response generation.
7A.2 Processing Purposes
Collected CosyAI data is processed for the following purposes:
• Generating personalized AI responses
• Creating socialization tasks and tracking progress
• Improving the quality of venue and event recommendations
• Improving and developing CosyAI service quality
7A.3 Legal Basis
Processing of personal data within the scope of CosyAI is based on the user's explicit consent under PDPL Article 5/1. The user is informed in detail about data processing before using CosyAI for the first time, and their explicit consent is obtained through a separate consent mechanism. The user has the right to withdraw their explicit consent at any time. In case of consent withdrawal, CosyAI chat history and learned preferences are deleted within 30 days. Withdrawal of consent does not affect the lawfulness of data processing activities carried out until the date of withdrawal.
7A.4 Third-Party Data Transfer (Google Gemini API)
User messages and context information are transferred to the Google Gemini API service for the generation of CosyAI responses. This transfer is made to Google servers located in the USA and is subject to the provisions on international data transfer under Article 9 of the PDPL. The transfer is based on the user's explicit consent. The principle of data minimization is applied to transferred data, and only the minimum data necessary for response generation is shared.
7A.5 Data Retention Period
CosyAI data is retained according to the following periods:
• Chat history and learned preferences are retained as long as the user account is active.
• In case of user deletion request or explicit consent withdrawal, CosyAI data is deleted within 30 days.
• In case of user account closure, CosyAI data is deleted within 30 days from the account closure date.
7A.6 User Rights
CosyAI users have the following rights in addition to their general rights under PDPL Article 11:
• Requesting deletion of CosyAI chat history
• Requesting reset of preferences learned by CosyAI
• Withdrawing explicit consent given for CosyAI data processing
• Objecting to automated analysis results by CosyAI under PDPL Article 11/1-h
To exercise these rights, you may apply to
[email protected] or use the in-app "Profile" > "Settings" > "Privacy" > "CosyAI Data" section.
8. Data Retention Period
Your personal data is retained for the duration required by the processing purposes and within the legal retention periods stipulated by the relevant legislation. Retention periods by data category are as follows:
• Account Data (name-surname, email, profile information): Retained as long as the account is active; deleted or anonymized within 30 days of account deletion request.
• Transaction/Payment Data: Retained for 10 years in accordance with the Turkish Commercial Code No. 6102 and the Tax Procedure Law No. 213.
• Analytics and Usage Data: Retained in anonymized form for a maximum of 2 years.
• Location Data: Real-time location data is not permanently stored on servers; it is only processed instantly for nearby venue listing.
• User-Generated Content (photos, reviews, etc.): Retained as long as the account is active; removed within 30 days upon account deletion request.
• Traffic Data (Law No. 5651): Retained for 2 years in accordance with Law No. 5651 and related regulations.
• CosyAI Data: CosyAI chat history and learned preferences are retained as long as the user account is active. In case of user deletion request or explicit consent withdrawal, they are deleted within 30 days.
• Account Deletion: After a user requests account deletion, personal data is deleted or anonymized within 30 days. Data subject to legal retention obligations is retained until the expiration of the relevant periods.
9. Data Security Measures
In accordance with Article 12 of the PDPL, the following technical and administrative measures are implemented to ensure the security of your personal data:
Technical Measures:
• Data transmission security is ensured through SSL/TLS encryption.
• Data is stored encrypted (AES-256) in AWS infrastructure.
• Access controls and role-based authorization mechanisms are implemented.
• Regular data backup operations are performed.
• Firewalls and intrusion detection systems are in use.
• Database access is logged and monitored.
Administrative Measures:
• Data processing activities are regularly reviewed.
• Data processing agreements are executed with third-party service providers.
• Access to personal data is restricted to authorized persons only.
• An emergency response plan is in place for data security breach situations.
10. Cookies and Tracking Technologies
The following cookie types and tracking technologies are used in the Cosyworker application:
1. Cookie Types:
• Strictly Necessary Cookies: Cookies mandatory for the basic functions of the application to operate (session management, authentication).
• Analytics/Performance Cookies: Used to collect information about the usage performance of the application.
• Functional Cookies: Used to remember user preferences (language selection, theme preferences).
• Advertising/Marketing Cookies: Used to measure ad impressions and campaign performance.
2. Third-Party Tracking Tools:
• Amplitude: Used for user behavior analysis and application performance monitoring. Device IDs and anonymized usage data are collected.
• Meta SDK (Facebook): Used for ad optimization and campaign performance measurement. Device IDs and ad interaction data are shared.
• Sentry: Used for application error tracking and crash reporting. Device IDs, error logs, and device metadata information are collected.
• Google Maps: Cookies required for map and location services are used.
3. Cookie Preference Management:
Users can manage cookie preferences from device settings or the "Settings" > "Privacy and Security" section within the application. You can disable cookies other than strictly necessary cookies; however, some application features may be restricted in this case.
11. Data Subject Rights (PDPL Article 11)
Within the scope of Article 11 of the PDPL, you have the following rights regarding your personal data:
1. Learning whether your personal data is processed;
2. Requesting information if your personal data has been processed;
3. Learning the purpose of processing your personal data and whether they are used in accordance with their purpose;
4. Knowing the third parties to whom your personal data has been transferred domestically or abroad;
5. Requesting correction of your personal data if it has been processed incompletely or incorrectly;
6. Requesting deletion or destruction of your personal data within the framework of conditions stipulated in Article 7 of the PDPL;
7. Requesting notification of correction, deletion, and destruction operations to third parties to whom your personal data has been transferred;
8. Objecting to the emergence of a result against the person himself/herself through the analysis of processed data exclusively by automated systems;
9. Requesting compensation for damages in case personal data is processed unlawfully.
Application Methods:
• Email: You can submit a written application to
[email protected] with information confirming your identity.
• In-App: You can create a request through "Profile" > "Settings" > "Privacy" > "Data Request" section.
Your applications will be concluded free of charge as soon as possible and within 30 (thirty) days at the latest, depending on the nature of your request. However, if the process requires an additional cost, the fee determined by the Personal Data Protection Board tariff may be charged.
Right to Complain to the Personal Data Protection Board: In cases where your application is rejected, the response is found insufficient, or no response is given within the time limit, you have the right to file a complaint with the Personal Data Protection Board within 30 days from the date you learn of the response and in any case within 60 days from the date of application.
12. Children's Privacy
The Cosyworker application is not intended for children under the age of 16 and does not knowingly collect personal data from individuals under the age of 16.
• Registration in the application by individuals under the age of 16 is prohibited.
• If a user is found to be under the age of 16, the relevant account and all personal data will be immediately deleted.
• If you believe that your child has provided personal data without our knowledge, please contact us immediately at
[email protected].
13. Data Breach Notification
In the event that a data breach is detected that compromises the security of your personal data:
• In accordance with Article 12/5 of the PDPL, the data breach will be reported to the Personal Data Protection Board as soon as possible and within 72 hours at the latest.
• Users affected by the breach will be informed within a reasonable time through in-app notifications and/or email.
• The notification will include the following information:
- When the breach occurred
- Affected data categories and estimated number of persons
- Possible consequences of the breach
- Measures taken and recommended to be taken
- Contact information
• In case of a data breach, additional security measures (password reset, session termination, etc.) may be applied depending on the scope of the data subject to the breach.
14. Policy Changes
This privacy policy may be updated from time to time due to legal regulations, changes in service conditions, or updates in application features.
• Significant changes to the policy will be announced through in-app notifications and/or your registered email address.
• In case of substantial changes in data processing purposes or scope, your explicit consent will be requested again when necessary.
• If you request access to previous versions of the policy, you can apply to
[email protected].
• Your continued use of the updated policy means that you accept the changes.
15. Contact and Application
For all questions, requests, and applications regarding your personal data:
Data Controller: Kudret Yılmaz
Address: Istanbul, Turkey
Email:
[email protected]
Application under the PDPL:
To exercise your rights regarding your personal data, you can apply to the email address specified above with a petition that includes information confirming your identity (name-surname, Turkish ID number, contact information) and clearly states your request.
Applications are concluded free of charge within 30 days at the latest. If the process requires an additional cost, the tariff determined by the Personal Data Protection Board applies.
Complaint to the Personal Data Protection Board:
In cases where your application is rejected, the response is found insufficient, or no response is given within the time limit, you can file a complaint with the Personal Data Protection Board (www.kvkk.gov.tr).