1. Data controller / service operator
F. Tugcenur Citak, trading online as TalkyMind, is responsible for the personal data described in this notice unless another provider is independently responsible for its own service.
Geographic business/contact address: Istanbul / Türkiye
Country of establishment: Türkiye
Email: [email protected]
Phone: +90 505 031 99 81
2. Data we process
Depending on what you choose to do, we may process your name, email address, optional phone number, optional location/region, selected time zone, requested appointment details, selected coaching service, practical coaching goal, correspondence, signed coaching agreement, limited payment evidence where Paid booking mode is used, invoice/billing information, cancellation/withdrawal statements and acknowledgement-delivery records, and security/technical records needed to protect the service.
We do not ask for diagnoses, medical records, treatment or medication information, national identity numbers, passwords, bank-login credentials or card numbers. Please do not place these in free-text fields or uploads. If unnecessary sensitive data is received, it may be deleted or redacted where practicable.
3. Purposes and legal grounds
| Purpose | Typical data | Legal reason used where applicable |
|---|---|---|
| Answer an enquiry | Identity, email, optional location, message | Steps requested before a possible contract and legitimate interests in responding to genuine enquiries. Where KVKK applies, the corresponding conditions may include Article 5(2)(c) (establishment/performance of a contract) and Article 5(2)(f) (legitimate interests, subject to the statutory balancing condition). |
| Create and administer a reservation | Identity, contact, appointment, time zone, coaching goal, agreement | Taking steps at your request before contract formation and performance/administration of a contract; compliance with legal obligations. Where KVKK applies, relevant conditions may include Article 5(2)(c) and Article 5(2)(ç). |
| Verify payment and issue accounting records | Payment reference/evidence only when a paid workflow is actually used; invoice details where applicable | Contract administration and legal/tax/accounting obligations. Inquiry / reservation mode does not request payment evidence. Where KVKK applies, relevant conditions may include Article 5(2)(c), Article 5(2)(ç) and, where needed for claims, Article 5(2)(e). |
| Process cancellation or withdrawal instructions | Reservation code, name, reservation email, statement, submission time and acknowledgement-delivery status | Contract administration, compliance with mandatory consumer-law duties where applicable, and establishment/exercise/defence of legal claims. Where KVKK applies, relevant conditions may include Article 5(2)(c), Article 5(2)(ç) and Article 5(2)(e). |
| Protect the website and prevent abuse | Session/security data and one-way rate-limit hashes | Legitimate interests in service security and, where applicable, legal obligations. Where KVKK applies, relevant conditions may include Article 5(2)(f) and Article 5(2)(ç). Raw IP addresses are not intentionally written into booking/contact records by the current workflow. |
| Cookie-free aggregate service measurement | Public page path (without query string), UTC date/hour, Cloudflare country code when available, coarse traffic-source/referrer category, primary request language, coarse device/browser/OS family, request method and response status. Request metadata is reduced immediately to aggregate counters. | Legitimate interests in understanding website reliability, content demand and service performance where that basis is available and the balancing test is satisfied. Where KVKK applies, the intended condition is Article 5(2)(f), subject to the statutory balancing requirement. No analytics visitor/session identifier, raw IP address, raw user-agent string, query string or full referrer URL is stored in this aggregate layer. Visitors can object, and DNT/GPC are respected. |
| Optional interaction analytics | Short-lived page/event statistics, random analytics session key and consented context such as coarse country/device, referrer host, UTM labels, locale/time zone and interaction events | Your optional consent/choice where consent is required. Where KVKK consent is the relied-on condition for personal-data analytics, Article 5(1) applies. Optional analytics is off until enabled through the privacy panel. |
| Marketing | None through the current booking/contact forms | The current public forms do not enroll clients in marketing. A future marketing feature would require a separate lawful basis and any consent/registration required by applicable law. |
Under Türkiye's KVKK, the exact processing condition depends on the activity and may include establishment/performance of a contract, compliance with a legal obligation, establishment/exercise/protection of a right, legitimate interests subject to the statutory balancing requirement, or explicit consent where the law specifically requires it. A privacy notice is not itself a consent request.
4. Recipients and service providers
Personal data is not sold. Data is shared only as reasonably necessary with categories such as hosting/CDN/security providers, email delivery providers, professional advisers, accountants, and competent public authorities where legally required. Google Analytics is loaded only if it is configured by the operator and you enable optional analytics. WhatsApp is not embedded as a tracker; if you choose to open a WhatsApp link, WhatsApp/Meta processes that interaction under its own terms and privacy information.
5. International transfers
Some infrastructure or communications providers may process data in more than one country. Where an international transfer is legally regulated, the operator must use the transfer mechanism required by the law applicable to that transfer before enabling the relevant provider - for example an adequacy mechanism, approved standard contractual safeguards or another lawful transfer route. Türkiye's current overseas-transfer framework is taken into account for transfers from Türkiye. You may ask for information about the safeguard used for a particular provider.
6. Retention schedule
Records are not intended to be kept indefinitely. The system applies the following operational schedule, subject to a documented legal hold, dispute, fraud/security investigation or a mandatory statutory period that requires a different duration.
| Record | Normal period | Why |
|---|---|---|
| Cookie/privacy preference records | 5 years after the preference is replaced or withdrawn | Demonstrating and administering privacy choices. |
| Cookie-free aggregate request statistics | 395 days by default | Coarse server-side traffic trends. Only aggregate counters are retained; no analytics visitor/session identifier, raw IP address, raw user-agent, query string or full referrer URL is stored in this layer. |
| Optional first-party analytics | 90 days by default | Short-term page and interaction measurement after opt-in. |
| Security/rate-limit hashes | Up to 30 days | Fraud, abuse and security protection. |
| Contact enquiries that do not become a booking | 12 months after the last recorded activity | Replying to the enquiry and handling reasonable follow-up. |
| Unsuccessful or incomplete reservations with no completed service | 12 months after the reservation ends | Reservation administration and dispute prevention. |
| Coaching-goal free text and optional scheduling/contact detail inside a finished booking | 24 months after the reservation/service ends, then minimised from the long-term booking record unless a documented legal hold requires longer | Short-term service administration while reducing long-term exposure of free-text and optional data. |
| Core contract evidence and signed agreement | Up to 10 years after the service relationship ends, unless the applicable statutory/claims period requires a shorter or longer period | Contract evidence and establishment, exercise or defence of legal claims where applicable. |
| Cancellation/withdrawal statements and acknowledgement records | Up to 10 years after submission, unless a shorter/longer mandatory period or documented legal hold applies | Proving receipt, timing and handling of cancellation/withdrawal instructions and related legal claims. |
| Reservation email history stored in the admin panel | 24 months after creation unless a documented dispute/legal hold requires longer | Operational follow-up; the client confirmation email remains the client's durable record. |
| Payment-receipt image/PDF | Normally 12 months after final confirmation/payment verification, then the uploaded proof is purged unless a dispute, legal hold or legal duty requires longer | Verifying payment while minimising retention of bank/payment evidence. |
| Invoices and statutory accounting records | 10 years after the relevant accounting period unless applicable law requires a different period | Tax, accounting and commercial record-keeping. |
| Marketing preference/evidence | While subscribed, plus up to 5 years after withdrawal for consent/objection evidence | Respecting marketing choices and demonstrating compliance. |
The application automatically performs periodic cleanup for short-lived analytics/security records, old contact enquiries, certain unsuccessful reservations and old payment-receipt uploads. Contract and statutory accounting records use the longer periods described above.
7. Cookies, local storage and analytics
An essential session cookie is used for security, CSRF protection, private reservation access and sign-in state. A browser local-storage item records your optional-analytics choice. Separately, the public site may increment cookie-free server-side aggregate counters from ordinary request metadata. That aggregate layer creates no analytics cookie, local-storage identifier, fingerprint or analytics visitor/session ID; it does not store raw IP addresses, raw user-agent strings, query strings or full referrer URLs. You may object to future aggregate measurement in ; the server then sets a privacy-preference cookie solely to honour that objection. DNT and Global Privacy Control are also respected by the application-level aggregate counter.
Optional first-party interaction analytics and optional Google Analytics do not start until you enable them. Optional first-party analytics may then record a random session key, page/event data and consented contextual fields for up to the configured short retention period. See the Cookie & Tracking Notice.
8. Your rights
You may request access to your information and, where the relevant law provides, correction, deletion, restriction, objection, data portability or withdrawal of a consent-based choice. Rights can be limited by statutory record-keeping duties, legal claims and other lawful exceptions. Requests can be sent to [email protected]. Identity may be verified proportionately before disclosing data.
If KVKK applies, the rights in Article 11 remain available. If EU/EEA GDPR applies to a particular processing activity, you may also have the right to complain to the competent supervisory authority. If UK data-protection law applies, you may have a right to complain to the UK Information Commissioner's Office. These references explain rights where mandatory law applies; they are not a statement that the service targets a particular country.
9. Automated decisions and children
The public booking workflow does not make solely automated decisions that produce legal or similarly significant effects. Availability checks prevent double-booking, but final acceptance is manual. The service is for adults aged 18 or over.
10. Changes and contact
This notice may be updated when the service, providers or law changes. Material changes should be versioned and presented before new data is collected where required. Questions or privacy requests: [email protected].