Personal Data Retention and Deletion Policy
PERSONAL DATA RETENTION AND DELETION POLICY
EmlakDiyo
Last updated: 1 September 2026
1. PURPOSE
This policy explains EmlakDiyo's retention and disposal rules under Turkish Law No. 6698 and the Regulation on Deletion, Destruction or Anonymisation of Personal Data. Publishing a policy does not itself complete compliance: expiry jobs must run and their results must be audited.
2. DATA CONTROLLER
Tolgahan Sönmez
Eroğlan Mah. İbni Sina Cad., Edremit / Balıkesir, Türkiye
info@emlakdiyo.com · +90 542 774 42 70
3. SCOPE AND ROLES
The policy covers the mobile app, website, web panel, Quick Portfolio extension, Türkiye-based server infrastructure, authorized administration, operational logs, and any backups. EmlakDiyo is controller for its account, subscription, and security data. An agent/office is controller for client records it enters, and EmlakDiyo acts as processor under authorized instructions.
4. RECORDING ENVIRONMENTS
- EmlakDiyo-managed PostgreSQL database and file storage in Türkiye
- App-specific local storage and caches on web/mobile clients
- Server, firewall, reverse-proxy, and application security logs
- MailGuard transactional-email delivery records
- Apple/Google store and purchase-verification records
- Firebase notification and Cloudflare Turnstile infrastructure
- Encrypted, access-restricted disaster-recovery backups if configured
5. REASONS FOR RETENTION
Data is kept only as needed to perform the membership/service contract, provide authorized office records, secure and maintain the service, verify purchases, prevent fraud, meet legal obligations and competent-authority requests, establish/exercise/defend rights, and manage disputes. When every processing reason ends and no legal obligation remains, data is deleted, destroyed, or anonymised.
6. RETENTION SCHEDULE
- Account/profile/membership: for membership; removed on account deletion subject to office-ownership and statutory-record exceptions.
- Personal CRM content: while membership/purpose continues. Warning after 11 months without app/web activity; eligible for cleanup only after 12 months of inactivity, successful warning delivery, and at least 30 further days. New activity cancels cleanup. Login and office membership remain.
- Office records: for the office service relationship and applicable legal period. Deleting an agent's personal account does not delete office-owned data.
- Deleted personal portfolios/files: may be made inaccessible first and permanently purged after 30 days, unless legally preserved.
- Listing/contact coordinates: for the life of the related record. Field-scan history: 90 days, then daily purge.
- Radar/valuation: request data is used to generate the output and protect/rate-limit the service. A saved report follows the related record's period; temporary technical records are limited to the shortest necessary period.
- Finance: voluntarily entered IBAN/account/invoice/transaction/tax-ID data is kept for the office relationship and applicable financial/legal period. EmlakDiyo never stores card number, CVV, or online-banking password.
- Store purchase verification: for subscription management, duplicate/fraud/dispute prevention, and legal duties; it excludes CRM content.
- Push token: while device registration remains active; removed from EmlakDiyo registration at sign-out, subject to provider processing time.
- Android Caller ID local list: until disabled, sign-out, or app-data removal. No call audio or uploaded call history is created.
- Office invite: 24 hours. Account-deletion confirmation: 5 minutes, single-use. Sensitive-action reauthentication: 10 minutes, purpose-bound and single-use. Auth confirmation/recovery/email-change links expire under the configured short auth-server period.
- Security/access/rate-limit logs: the shortest period needed for incident review, security, and law; not indefinitely. Account-deletion audit: at least 36 months or a longer mandatory period.
- Public analytics: only after consent; Google analytics cookies may remain for up to two years depending on configuration. The consent choice remains locally until changed or browser data is cleared.
- Extension draft: not persisted by the extension; removed from the address bar after reading. A saved draft follows portfolio retention.
7. DISPOSAL METHODS
Deletion removes data from accessible user systems and, after any soft-delete period, from database and associated storage. Destruction makes media data unrecoverable using a method suited to that medium. Anonymisation prevents re-identification by reasonable means; pseudonymisation alone is not anonymisation.
8. BACKUPS
When backups are enabled, they must be encrypted, access-restricted, separate from production, and used only for disaster recovery. Deleted data remaining in a backup is destroyed through normal rotation and must not be restored for another purpose. Backup periods and restore tests must be documented operationally; this policy does not claim that an unconfigured backup process exists.
9. PERIODIC DISPOSAL AND RESPONSIBILITY
Automated scheduled jobs and administrative reviews scan expired data. The general periodic-disposal interval does not exceed six months; records with shorter periods are purged at those periods. Technical operations run database/file/backup jobs and keep disposal evidence. The controller manages requests, legal holds, provider contracts, and periodic review. Office managers are responsible for authorized use and lawful instructions for their office data.
Disposal type, date, scope, and result are logged. These disposal records are kept for at least three years unless another legal period applies.
10. ACCOUNT DELETION AND REQUESTS
Account deletion starts in the app or at emlakdiyo.com/delete-account. After identity verification, personal account/content is removed; office-owned records, mandatory transfers, deletion audit, and statutory records are excluded. Store subscriptions must be cancelled separately.
KVKK Article 11 requests may be sent to info@emlakdiyo.com and are answered within 30 days. Where deletion conditions exist, data is disposed of at the first applicable periodic-disposal date under the law.
11. INTERNATIONAL SERVICES
The core database, authentication, files, and transactional email are in Türkiye. Firebase, Apple, Cloudflare, OpenStreetMap, and store services have their own retention/deletion processes and require separate management of the Article 9 transfer mechanism. Current recipients and transfer details appear in the Privacy Policy and KVKK Notice.