KVKK Disclosure Notice
Last updated: 14.08.2026
1. Identity of the data controller
- Data controller
- Halid Tosun (AURCAM)
- Electronic mail
- kvkk@aurcam.com
- Alternative contact
- privacy@aurcam.com
- Website
- https://aurcam.com
AURCAM is a social media platform that can be reached through iOS, Android, macOS, Windows and the web. This notice covers every version of the platform.
2. Categories of personal data processed
- Identity data
- First name, surname (display name), username, date of birth, optional gender information.
- Contact data
- E-mail address.
- Transaction security data
- Password hash (bcrypt), session records, IP address, device information, two-step verification records, sign-in times.
- Visual and audio data
- Profile photo, the photos and videos you share, voice messages, audio/video room content.
- Location data
- Only with your explicit consent; for the map and digital footprint features. Raw coordinates are not written to server logs.
- Customer transaction data
- Subscription status, purchase records, coin balance and spending history.
- Marketing data
- Only if you have given your consent: newsletter subscription and communication preferences.
- Legal transaction data
- Complaint, moderation and appeal records; requests from competent authorities.
3. Purposes of processing
- Creating the membership record and managing the account.
- Providing the social media service: feed, stories, reels, messaging, map, audio/video rooms.
- Content moderation and the prevention of abuse and fraud.
- Ensuring account security (two-step verification, session management, detection of suspicious sign-ins).
- Personalising the user experience (feed ranking, recommendations).
- Operating the subscription and payment processes, and invoicing.
- Assessing requests, complaints and appeals; providing support.
- Fulfilling legal obligations and responding to requests from competent authorities.
- Improving the service, debugging and performance analysis.
4. Legal grounds (KVKK arts. 5–6)
- Conclusion and performance of a contract (art. 5/2-c)
- Creating an account, providing the service, managing subscriptions.
- Legal obligation (art. 5/2-ç)
- Retaining records as required by tax and commercial legislation; requests from competent authorities.
- Legitimate interest (art. 5/2-f)
- Security, prevention of abuse, moderation, improvement of the service.
- Data made public by the data subject themselves (art. 5/2-d)
- The posts and profile information you share publicly.
- Explicit consent (art. 5/1)
- Location data, marketing communications and optional personalisation. You may withdraw your consent at any time.
5. Method of collection
Your personal data is collected through the mobile applications, the desktop applications and the web interface by wholly or partly automated means, both from what you enter directly (registration form, content sharing, support request) and from records generated automatically during use (session, device and error logs).
6. Parties to whom data is transferred
- Hosting provider
- netcup GmbH (Germany) — server and data centre services.
- Payment institutions
- Apple and Google (in-app purchases) and Dodo Payments (web payments). Your card details never reach us.
- Notification services
- Apple Push Notification service and Firebase Cloud Messaging — only the minimum data required to deliver the notification.
- Content services
- Deezer (music previews), GIPHY (GIF search), OpenFreeMap (map tiles). Your user identity is not transferred.
- Competent public institutions and organisations
- Only where there is a duly made, legally binding request, and limited to the scope of that request.
Your personal data is never sold or rented to any third party for marketing purposes.
7. Transfers abroad
Because our servers are located in Germany, your data is processed outside Türkiye, within the European Union. In addition, limited data may be transferred to the countries in which the notification and payment service providers are located. These transfers are made within the framework of the safeguards required by Article 9 of the KVKK (undertakings / standard contractual clauses).
8. Retention and destruction periods
- Membership and content data
- For as long as the membership continues; after a request to delete the account, destroyed immediately from production systems and within 30 days at the latest from backups.
- Session and security records
- 90 days (may be longer for incidents that require a security investigation).
- Moderation and complaint records
- 2 years.
- Invoice, payment and financial records
- 10 years, as required by the Tax Procedure Law and the Turkish Commercial Code.
- Support correspondence
- 3 years.
- Error logs
- 30 days.
Data whose retention period has expired is deleted, destroyed or anonymised as part of periodic destruction.
9. Your rights under Article 11 of the KVKK
As a data subject, you have the following rights:
- To learn whether your personal data is being processed.
- To request information about it if it has been processed.
- To learn the purpose of the processing and whether the data is used in line with that purpose.
- To know the third parties to whom the data has been transferred, in Türkiye or abroad.
- To request rectification if the data has been processed incompletely or incorrectly.
- To request erasure or destruction within the framework of Article 7 of the KVKK.
- To request that rectification, erasure and destruction be notified to the third parties to whom the data was transferred.
- To object to a result to your detriment arising from analysis carried out exclusively by automated systems.
- To claim compensation for the damage if you suffer damage because of unlawful processing.
10. How to apply and the process
You can send your requests to kvkk@aurcam.com, together with information that allows us to verify your identity. Your application is concluded free of charge within 30 days at the latest. Where the process entails an additional cost, the fee in the tariff determined by the Board may be charged.
Some requests you can carry out instantly from within the app: Settings → Privacy → Download my data and Settings → Privacy → Delete account.
If your application is rejected, if you find our answer inadequate or if no answer is given within the period, your right to lodge a complaint with the Personal Data Protection Board is reserved.
11. Administrative and technical measures taken
Technical measures
- TLS 1.2+ encryption on all network traffic; unencrypted connections are not accepted.
- Passwords hashed with bcrypt; storing or logging them in plain text is prohibited.
- Intrusion detection and automatic IP blocking (fail2ban), and rate limiting.
- Authorisation checks enforced on the server side; the client is not trusted.
- Encrypted and regular database backups.
- Dependency updates and regular security audits.
Administrative measures
- Role-based access authorisation and the principle of least privilege.
- All administrator actions written to an audit log.
- Contractual confidentiality obligations with data processors.
- Data breach response procedure: on detection, the data subjects concerned and the Board are informed as soon as possible.
Questions? support@aurcam.com · Contact page